We are looking for a senior researcher with deep practical experience identifying and exploiting vulnerabilities across Chrome sandbox boundaries on Android. You should already know how to move from a compromised renderer or low-privilege browser process to a meaningful trust-boundary violation. The goal is stable, chainable sandbox-escape capability on real Android targets. What you’ll work on - Renderer-accessible Mojo interfaces, interface brokers and browser-process endpoints. - GPU, media, network, utility, device and other services reachable from low-privilege Chrome processes. - Android-specific Chrome integration, including platform bridges, Binder-facing components, permissions and service boundaries. - Confused-deputy conditions, validation gaps, unsafe deserialisation, lifetime errors, races and state-machine mistakes. - Cross-process exploitation where asynchronous IPC, handles, shared memory or capability transfer affect reliability. - End-to-end chains with renderer and Android-kernel researchers when needed. What you’ll deliver - Original vulnerabilities that cross a Chrome process, privilege or trust boundary on Android. - Reliable sandbox-escape exploit components that work under production mitigations. - Prioritised attack-surface areas that are deemed to be complex enough to contain vulnerabilities. - Triggers, PoCs, exploitability analysis, target assumptions and complete technical handover. - Reusable tooling for IPC discovery, Mojo message generation, tracing, instrumentation, coverage and variant analysis. What we’re looking for - Demonstrable delivery of Chrome/Chromium sandbox escapes, browser-process vulnerabilities or closely comparable cross-privilege exploitation. - Deep knowledge of Chromium’s multi-process architecture, sandbox policy and renderer-to-browser trust boundaries. - Strong practical experience with Mojo IPC, bindings, data pipes, shared memory, interface ownership and message validation. - Advanced C++ vulnerability-research and exploitation skills in complex multi-process targets. - Working knowledge of Android internals relevant to Chrome, including application isolation, SELinux domains, Binder and platform services. - The ability to turn a subtle boundary mistake into a stable result that can be integrated into a wider chain. - Independent research ownership and a consistent history of finishing high-difficulty work. Strong signals - Credited Chrome sandbox escapes or comparable real-world cross-privilege exploit delivery. - Custom Mojo fuzzers, IPC introspection tools or Chrome instrumentation frameworks. - Experience chaining renderer compromise through sandbox escape to Android system or kernel impact. - Research across multiple Android OEMs, chipsets and Chrome branches. - vulnerabilities found made it to stable/beta releases. - Strong patch-analysis and variant-hunting results. How we work - Fully remote, with high autonomy and close collaboration between browser, platform and kernel specialists. - We measure progress through technically meaningful, reproducible delivery. - Public CVEs are not a requirement.
Browser - Vulnerability Researcher
Trenchant
iOS User Space Sandbox Escape - Vulnerability Researcher
Trenchant
Vulnerability Researcher - Global (All Levels)
Trendmicro
Shopify Web Developer - Feel Your Soul
Shadow Light Studios
Cyber Software Engineer
Breakpoint Research
Director, Business Relationship Management - Customer Experience 2373181 | Eden Prairie, Minnesota | Remote
Tas Uhg