---
title: "Google built an AI burglar and gave it a badge"
description: "PageBreak has found 500-plus real bugs in Google’s own web apps by refusing to report anything it can’t actually exploit"
author: "Tomasz Idle"
published: 2026-09-25T19:16:04Z
modified: 2026-09-26T17:00:38Z
url: https://rews.cc/a/google-built-an-ai-burglar-and-gave-it-a-badge-978767
language: en
tags: ["ai", "security", "google", "cybersecurity", "automation", "tech"]
publisher: "Rews (https://rews.cc)"
---

# Google built an AI burglar and gave it a badge

*PageBreak has found 500-plus real bugs in Google’s own web apps by refusing to report anything it can’t actually exploit*

By Tomasz Idle · September 25, 2026 · https://rews.cc/a/google-built-an-ai-burglar-and-gave-it-a-badge-978767

## In brief

- Google disclosed PageBreak, an internal Gemini-based AI agent that autonomously hunts vulnerabilities in its first-party web apps
- The agent validates every suspected flaw with a working exploit on a live application, for a near-zero false-positive rate
- PageBreak has found over 500 XSS vulnerabilities since piloting in November 2025 and going full-scale in January 2026
- Against Google’s high-assurance web frameworks, PageBreak found only two bugs—evidence for building safety in structurally
- Google plans to link PageBreak with CodeMender, its automated patch-writing agent, so bugs arrive with proposed fixes

Every neighborhood watch eventually faces the same temptation: the people who know the locks best are the ones who pick them. Google has now made this official. The company disclosed on September 24 that its Product Security team has built an AI agent named PageBreak whose entire job is to break into Google’s web applications—an in-house burglar with an employee badge, a pension plan presumably, and a strict rule that it may only speak up about a lock after it has personally opened it.

That rule is the whole invention, and it’s worth understanding why. For two years, security teams everywhere have been drowning in what Google itself calls “AI slop”: bug reports generated by chatbots that read like vulnerabilities and behave like fan fiction. “Distinguishing a genuine, exploitable flaw from a convincing hallucination has become a major challenge,” the company wrote in a blog post by information security engineer Michał Bentkowski. Ask a language model to find a security hole and it will find one, instantly, whether or not one exists. The epistemology of a golden retriever: everything found is a stick.

PageBreak, built on Google’s Gemini models, was designed so that a human never has to grade that homework. When the agent suspects a flaw, it hands the hypothesis to a specialized validator that attempts an actual working exploit against a live, running copy of the application. Only a vulnerability that survives this audition gets reported—giving the system, according to Google, a near-zero false-positive rate. Starting as a pilot in November 2025 and becoming a full project in January 2026, its stated mission is “to autonomously scale vulnerability discovery while minimizing manual toil.”

So far it has found more than 500 XSS vulnerabilities—cross-site scripting flaws—in Google’s first-party web applications. That’s the bug class that lets an attacker hijack a logged-in session, steal data, or impersonate a user on a site people use every day. Five hundred is either a triumph for the AI or a quiet statement about the software, and it is polite not to ask Google which.

Actually, Google answered that question itself, in the most interesting number in the disclosure. Run against applications built on Google’s newer “high-assurance” web frameworks—frameworks designed to make entire bug classes structurally impossible, rather than patchable—PageBreak found just two. The company presents this as evidence that building safer software from the start beats finding holes afterward. It is good evidence. It is also a 250-to-1 ratio between the old way of writing software and the new way, published voluntarily by the party that did it the old way a lot.

The timing is not subtle. AI agents on the offensive side have had a busy year. In August, more than 100 organizations—Google, Microsoft and Anthropic among them—signed an open letter warning that AI-enabled cyberattacks are becoming more common, after agents from OpenAI and Anthropic breached real companies during testing. Since then we’ve watched [an OpenAI agent walk past its own blocks into Australian government files](https://rews.cc/a/openai-agent-broke-past-blocks-into-australian-government-fi-695053), and researchers [ride two flaws and an AI agent into OpenAI’s internal code store](https://rews.cc/a/how-two-flaws-and-an-ai-agent-carried-researchers-into-opena-869c96). PageBreak is the other face of the same coin: an autonomous attacker pointed at its employer. Google has also been on the receiving end of its own toolchain before, having had to patch one of its AI coding tools after a flaw let attackers execute malicious code through it.

Google notes, fairly, that rivals can’t easily copy this: PageBreak leans on a single unified repository of billions of lines of code and years of internal scanning infrastructure. The burglar knows the house because the burglar helped build it. The next step is pairing it with CodeMender, Google’s automated patch-writing agent, so a confirmed vulnerability arrives with a proposed fix attached, leaving human engineers to review rather than repair.

Which completes the loop nicely: one AI to write the code, one to break it, one to fix it, and a shrinking committee of people to sign the paperwork. The burglar got a badge because the burglar was always going to be smarter than the locks. The only question the industry keeps declining to answer is how many burglars there are, and Google just measured one corner of that too: five hundred locks, and counting.
