We are looking for a deeply experienced iOS userspace researcher who has already delivered sandbox escapes, privileged-daemon vulnerabilities or equivalent exploit components. The work is focused on real trust boundaries exposed through Mach, XPC, private frameworks, privileged services and entitlement-gated functionality. This is not an application-security or jailbreak-usage role. What you’ll work on - Privileged iOS daemons, frameworks and services reachable from sandboxed application or browser contexts. - Mach, XPC, NSXPC, serialisation and object-bridging boundaries. - Memory corruption, logic vulnerabilities, confused-deputy conditions, race conditions and entitlement bypasses. - Sandbox profiles, service registration, entitlement checks and cross-process trust relationships. - Private-framework and daemon-protocol reverse engineering across iOS releases and arm64e devices. - Exploit-chain integration with browser and kernel researchers when required. What you’ll deliver - Original iOS userspace vulnerabilities that cross sandbox, entitlement, process or service boundaries. - Reliable sandbox-escape exploit components suitable for integration into broader chains. - Prioritised attack-surface maps for privileged services, framework brokers and entitlement-gated functionality. - Triggers, PoCs, exploitation strategy, affected-version notes, assumptions and clear technical handover. - Reusable tooling for service discovery, message generation, daemon instrumentation, entitlement analysis and variant research. What we’re looking for - Proven delivery of iOS sandbox escapes, privileged-daemon vulnerabilities or comparable userspace exploit components. - Deep knowledge of iOS process isolation, code signing, entitlements, sandbox profiles and launch/service models. - Strong reverse engineering across Objective-C, Swift and C/C++, including private frameworks and stripped binaries. - Practical expertise with Mach messaging, XPC/NSXPC, serialisation formats and asynchronous service interactions. - Advanced ARM64/arm64e userspace exploitation, including modern heap behaviour, PAC-aware strategies and constrained code execution. - The ability to reason about chainability, target variation and reliability rather than stopping at a one-time daemon crash. - A consistent history of independently finishing complex research. Strong signals - Public iOS security credits, jailbreak-chain research or comparable exploit-chain delivery. - Experience chaining browser compromise into an iOS userspace sandbox escape. - Custom XPC/Mach fuzzing, service-introspection or firmware-analysis tooling. - Research across multiple major iOS generations and arm64e hardware families. - Strong patch-diffing and variant-hunting results. How we work - Fully remote, with high autonomy and direct collaboration with browser and kernel specialists. - We value technically meaningful delivery, clean handover and reproducibility over activity metrics or polished theatre. - Public CVEs are useful but not required.
Browser - Vulnerability Researcher
Trenchant
Chrome Sandbox Escape Android - Vulnerability Researcher
Trenchant
Vulnerability Researcher - Global (All Levels)
Trendmicro
Shopify Web Developer - Feel Your Soul
Shadow Light Studios
Cyber Software Engineer
Breakpoint Research
Head of Supply Chain, DTC Health & Wellness
Hyprwork