Blog.Google Google's PageBreak Project Identifies 500+ XSS Vulnerabilities
Article Content
- •PageBreak identified over 500 XSS vulnerabilities in Google applications.
- •Only two vulnerabilities were found in hardened applications, supporting secure coding practices.
- •The project uses a two-stage validation process to minimize false positives.
Google's PageBreak project has validated over 500 cross-site scripting (XSS) vulnerabilities across its first-party web applications, with only two found in applications using hardened frameworks. The project, which began as a pilot in November 2025 and became fully operational in January 2026, employs Gemini models for vulnerability detection and a two-stage validation process to ensure low false-positive rates. The validation process involves executing real payloads to confirm the existence of vulnerabilities. This approach has proven effective, as the majority of findings were in applications not built on secure-by-design architectures. The results highlight the effectiveness of secure coding practices in reducing vulnerabilities. The findings were disclosed in a blog post by Michał Bentkowski on September 24, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-34219 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed