Chrome Sandbox Escape Android - Vulnerability Researcher

Trenchant

United States

Remote

USD 180,000 - 240,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Trenchant is seeking a senior researcher with deep practical experience identifying and exploiting vulnerabilities across Chrome sandbox boundaries on Android. You should be capable of moving from a compromised renderer to a trust-boundary violation, delivering stable, chainable sandbox-escape exploits on real targets.

You will develop exploits, PoCs, and tooling for IPC discovery, Mojo message generation, tracing, and variant analysis, working remotely with autonomy and cross-functional

Qualifications

  • Proven delivery of sandbox escapes or cross-privilege exploits.
  • Deep knowledge of Chromium multi-process architecture and trust boundaries.
  • Strong practical experience with Mojo IPC, data pipes and shared memory.
  • Advanced C++ vulnerability-research and exploitation skills.
  • Experience with Android internals related to Chrome (Binder, SELinux).

Responsibilities

  • Identify and exploit vulnerabilities across Chrome sandbox boundaries on Android.
  • Develop reliable, chainable sandbox-escape exploits for real targets.
  • Deliver PoCs, exploitability analyses, and technical handover.
  • Create reusable IPC discovery and instrumentation tooling.
  • Collaborate across browser, platform and kernel domains remotely.

Skills

Chromium sandbox escapes
Chromium multi-process arch
Mojo IPC
C++ vulnerability research
Android internals (Binder/SELinux)
Independent research ownership

Tools

Mojo debugging tools
IPC introspection tooling

Job description

We are looking for a senior researcher with deep practical experience identifying and exploiting vulnerabilities across Chrome sandbox boundaries on Android.

You should already know how to move from a compromised renderer or low-privilege browser process to a meaningful trust-boundary violation. The goal is stable, chainable sandbox-escape capability on real Android targets.

What you’ll work on
  • Renderer-accessible Mojo interfaces, interface brokers and browser-process endpoints.

  • GPU, media, network, utility, device and other services reachable from low-privilege Chrome processes.

  • Android-specific Chrome integration, including platform bridges, Binder-facing components, permissions and service boundaries.

  • Confused-deputy conditions, validation gaps, unsafe deserialisation, lifetime errors, races and state-machine mistakes.

  • Cross-process exploitation where asynchronous IPC, handles, shared memory or capability transfer affect reliability.

  • End-to-end chains with renderer and Android-kernel researchers when needed.

What you’ll deliver
  • Original vulnerabilities that cross a Chrome process, privilege or trust boundary on Android.

  • Reliable sandbox-escape exploit components that work under production mitigations.

  • Prioritised attack-surface areas that are deemed to be complex enough to contain vulnerabilities.

  • Triggers, PoCs, exploitability analysis, target assumptions and complete technical handover.

  • Reusable tooling for IPC discovery, Mojo message generation, tracing, instrumentation, coverage and variant analysis.

What we’re looking for
  • Demonstrable delivery of Chrome/Chromium sandbox escapes, browser-process vulnerabilities or closely comparable cross-privilege exploitation.

  • Deep knowledge of Chromium’s multi-process architecture, sandbox policy and renderer-to-browser trust boundaries.

  • Strong practical experience with Mojo IPC, bindings, data pipes, shared memory, interface ownership and message validation.

  • Advanced C++ vulnerability-research and exploitation skills in complex multi-process targets.

  • Working knowledge of Android internals relevant to Chrome, including application isolation, SELinux domains, Binder and platform services.

  • The ability to turn a subtle boundary mistake into a stable result that can be integrated into a wider chain.

  • Independent research ownership and a consistent history of finishing high-difficulty work.

Strong signals
  • Credited Chrome sandbox escapes or comparable real-world cross-privilege exploit delivery.

  • Custom Mojo fuzzers, IPC introspection tools or Chrome instrumentation frameworks.

  • Experience chaining renderer compromise through sandbox escape to Android system or kernel impact.

  • Research across multiple Android OEMs, chipsets and Chrome branches.

  • vulnerabilities found made it to stable/beta releases.

  • Strong patch-analysis and variant-hunting results.

How we work
  • Fully remote, with high autonomy and close collaboration between browser, platform and kernel specialists.

  • We measure progress through technically meaningful, reproducible delivery.

  • Public CVEs are not a requirement.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Android Chrome Sandbox Exploitation Researcher
Senior Android Chrome Sandbox Exploitation Researcher

Trenchant • United States

Remote
USD 180,000 - 240,000
iOS User Space Sandbox Escape - Vulnerability Researcher
iOS User Space Sandbox Escape - Vulnerability Researcher

Trenchant • United States

Remote
USD 180,000 - 260,000
Fully remote
Android Kernel - Exploit Developer
Android Kernel - Exploit Developer

Trenchant • United States

Remote
USD 160,000 - 230,000
Remote Senior iOS Exploit Researcher — Sandbox & Privileged
Remote Senior iOS Exploit Researcher — Sandbox & Privileged

Trenchant • United States

Remote
USD 180,000 - 260,000
Fully remote
Android Exploitation Engineer APPLIED AI VR ANDROID New York, NY / On Site →
Android Exploitation Engineer APPLIED AI VR ANDROID New York, NY / On Site →

Zealot Labs, Inc. • New York (NY), Northern (KY)

On-site
USD 100,000 - 195,000
Equity
Remote Senior Android Kernel Exploit Engineer
Remote Senior Android Kernel Exploit Engineer

Trenchant • United States

Remote
USD 160,000 - 230,000
Android Vulnerability Researcher
Android Vulnerability Researcher

TopClearedRecruiting • United States

On-site
USD 120,000 - 180,000
Competitive base salary
Project-based performance bonuses
Flexible work schedule
X-Day Offensive Research (XOR) Vulnerability Researcher
X-Day Offensive Research (XOR) Vulnerability Researcher

JPMorgan Chase & Co. • Jersey City (NJ)

On-site
USD 150,000 - 230,000
ChromeOS Platform Engineer
ChromeOS Platform Engineer

Tenarai • New York (NY)

On-site
USD 180,000 - 280,000
Browser / Kernel Engineer
Browser / Kernel Engineer

SearchApi • United States

On-site
CLP 64,754,856 - 83,256,244
Equity share
Profit sharing
Fully remote work
+1