Chrome Sandbox Escape Android - Vulnerability Researcher @Trenchant
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted 2mths ago

[Hiring] Chrome Sandbox Escape Android - Vulnerability Researcher @Trenchant

2mths ago - Trenchant is hiring a remote Chrome Sandbox Escape Android - Vulnerability Researcher. 💸 Salary: unspecified 📍Location: Worldwide

Role Description

We are looking for a senior researcher with deep practical experience identifying and exploiting vulnerabilities across Chrome sandbox boundaries on Android. You should already know how to move from a compromised renderer or low-privilege browser process to a meaningful trust-boundary violation. The goal is stable, chainable sandbox-escape capability on real Android targets.

What you’ll work on

  • Renderer-accessible Mojo interfaces, interface brokers and browser-process endpoints.
  • GPU, media, network, utility, device and other services reachable from low-privilege Chrome processes.
  • Android-specific Chrome integration, including platform bridges, Binder-facing components, permissions and service boundaries.
  • Confused-deputy conditions, validation gaps, unsafe deserialisation, lifetime errors, races and state-machine mistakes.
  • Cross-process exploitation where asynchronous IPC, handles, shared memory or capability transfer affect reliability.
  • End-to-end chains with renderer and Android-kernel researchers when needed.

What you’ll deliver

  • Original vulnerabilities that cross a Chrome process, privilege or trust boundary on Android.
  • Reliable sandbox-escape exploit components that work under production mitigations.
  • Prioritised attack-surface areas that are deemed to be complex enough to contain vulnerabilities.
  • Triggers, PoCs, exploitability analysis, target assumptions and complete technical handover.
  • Reusable tooling for IPC discovery, Mojo message generation, tracing, instrumentation, coverage and variant analysis.

Qualifications

  • Demonstrable delivery of Chrome/Chromium sandbox escapes, browser-process vulnerabilities or closely comparable cross-privilege exploitation.
  • Deep knowledge of Chromium’s multi-process architecture, sandbox policy and renderer-to-browser trust boundaries.
  • Strong practical experience with Mojo IPC, bindings, data pipes, shared memory, interface ownership and message validation.
  • Advanced C++ vulnerability-research and exploitation skills in complex multi-process targets.
  • Working knowledge of Android internals relevant to Chrome, including application isolation, SELinux domains, Binder and platform services.
  • The ability to turn a subtle boundary mistake into a stable result that can be integrated into a wider chain.
  • Independent research ownership and a consistent history of finishing high-difficulty work.

Strong signals

  • Credited Chrome sandbox escapes or comparable real-world cross-privilege exploit delivery.
  • Custom Mojo fuzzers, IPC introspection tools or Chrome instrumentation frameworks.
  • Experience chaining renderer compromise through sandbox escape to Android system or kernel impact.
  • Research across multiple Android OEMs, chipsets and Chrome branches.
  • Vulnerabilities found made it to stable/beta releases.
  • Strong patch-analysis and variant-hunting results.

How we work

  • Fully remote, with high autonomy and close collaboration between browser, platform and kernel specialists.
  • We measure progress through technically meaningful, reproducible delivery.
  • Public CVEs are not a requirement.
Before You Apply
️
worldwide Be aware of the location restriction for this remote position: Worldwide
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Chrome Sandbox Escape Android - Vulnerability Researcher @Trenchant
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted 2mths ago
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
️
worldwide Be aware of the location restriction for this remote position: Worldwide
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
×
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 ★★★★★ from 500+ reviews

⚡ 127,023+ remote jobs, refreshed hourly

🔔 Real-time alerts: Apply first, direct to employer

🛡️ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later