Relomote
Remote JobsRelocation Jobs
Add companySaved
Relomote

Relomote is a job board for remote, hybrid, and relocation jobs — every listing AI-classified for the countries it actually hires from, or the visa and relocation support it offers.

LinkedInCrunchbase

Remote jobs by category

  • Remote Engineering & Development jobs
  • Remote Customer Support jobs
  • Remote Design jobs
  • Remote Marketing jobs
  • Remote Sales jobs
  • Remote Product jobs
  • Remote Data & Analytics jobs
  • Remote People & Talent jobs
  • Remote Writing & Content Creation jobs
  • Remote Finance jobs
  • Remote Legal & Compliance jobs
  • Remote Operations & Admin jobs
  • Remote Data Entry jobs
  • Remote Virtual Assistant jobs
  • Remote Education/Training jobs
  • Remote Healthcare/Clinical jobs
  • Remote Other jobs

Remote jobs by location

  • Work from anywhere jobs
  • Remote jobs in Africa
  • Remote jobs in Asia
  • Remote jobs in Europe
  • Remote jobs in Latin America
  • Remote jobs in Middle East
  • Remote jobs in North America
  • Remote jobs in Oceania
  • All remote jobs →

Relocation & visa sponsorship

  • Visa sponsorship jobs
  • Relocation package jobs
  • Relocate to Europe
  • Relocate to Germany
  • Relocate to Netherlands
  • Relocate to Spain
  • Relocate to Portugal
  • Relocate to Greece
  • Relocate to United Kingdom
  • Relocate to Canada
  • Relocate to Australia
  • Relocate to Sweden
  • Relocate to Switzerland
  • Relocate to Japan
  • Relocate to United Arab Emirates
  • All relocation jobs →

© 2026 RelomoteAboutPrivacyTerms

Contact [email protected] · Built by Mahmoud

Relomote
Remote JobsRelocation Jobs
Add companySaved
Trenchant logo

Chrome Sandbox Escape Android - Vulnerability Researcher

Trenchant
Posted Yesterday
🌍Worldwide🏠Remote📁Engineering & Development
Is this job info correct?

We are looking for a senior researcher with deep practical experience identifying and exploiting vulnerabilities across Chrome sandbox boundaries on Android. You should already know how to move from a compromised renderer or low-privilege browser process to a meaningful trust-boundary violation. The goal is stable, chainable sandbox-escape capability on real Android targets. What you’ll work on - Renderer-accessible Mojo interfaces, interface brokers and browser-process endpoints. - GPU, media, network, utility, device and other services reachable from low-privilege Chrome processes. - Android-specific Chrome integration, including platform bridges, Binder-facing components, permissions and service boundaries. - Confused-deputy conditions, validation gaps, unsafe deserialisation, lifetime errors, races and state-machine mistakes. - Cross-process exploitation where asynchronous IPC, handles, shared memory or capability transfer affect reliability. - End-to-end chains with renderer and Android-kernel researchers when needed. What you’ll deliver - Original vulnerabilities that cross a Chrome process, privilege or trust boundary on Android. - Reliable sandbox-escape exploit components that work under production mitigations. - Prioritised attack-surface areas that are deemed to be complex enough to contain vulnerabilities. - Triggers, PoCs, exploitability analysis, target assumptions and complete technical handover. - Reusable tooling for IPC discovery, Mojo message generation, tracing, instrumentation, coverage and variant analysis. What we’re looking for - Demonstrable delivery of Chrome/Chromium sandbox escapes, browser-process vulnerabilities or closely comparable cross-privilege exploitation. - Deep knowledge of Chromium’s multi-process architecture, sandbox policy and renderer-to-browser trust boundaries. - Strong practical experience with Mojo IPC, bindings, data pipes, shared memory, interface ownership and message validation. - Advanced C++ vulnerability-research and exploitation skills in complex multi-process targets. - Working knowledge of Android internals relevant to Chrome, including application isolation, SELinux domains, Binder and platform services. - The ability to turn a subtle boundary mistake into a stable result that can be integrated into a wider chain. - Independent research ownership and a consistent history of finishing high-difficulty work. Strong signals - Credited Chrome sandbox escapes or comparable real-world cross-privilege exploit delivery. - Custom Mojo fuzzers, IPC introspection tools or Chrome instrumentation frameworks. - Experience chaining renderer compromise through sandbox escape to Android system or kernel impact. - Research across multiple Android OEMs, chipsets and Chrome branches. - vulnerabilities found made it to stable/beta releases. - Strong patch-analysis and variant-hunting results. How we work - Fully remote, with high autonomy and close collaboration between browser, platform and kernel specialists. - We measure progress through technically meaningful, reproducible delivery. - Public CVEs are not a requirement.

Similar jobs

Similar jobs

Trenchant logo

Browser - Vulnerability Researcher

Trenchant

🌍WorldwideYesterday
Trenchant logo

iOS User Space Sandbox Escape - Vulnerability Researcher

Trenchant

🌍WorldwideYesterday
Trendmicro logo

Vulnerability Researcher - Global (All Levels)

Trendmicro

🌍Worldwide3 weeks ago
Shadow Light Studios logo

Shopify Web Developer - Feel Your Soul

Shadow Light Studios

🌍Worldwide7 hours ago
BR

Cyber Software Engineer

Breakpoint Research

🌍Worldwide15 hours ago
Tas Uhg logo

Director, Business Relationship Management - Customer Experience 2373181 | Eden Prairie, Minnesota | Remote

Tas Uhg

🌍Worldwide6 hours ago