Trenchant

Chrome Sandbox Escape Android - Vulnerability Researcher

Trenchant

IT Services and IT Consulting · 2-10 employees

2 d ago
Remote Senior (5-10 yrs) Full-time
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The researcher will identify and exploit vulnerabilities across Chrome sandbox boundaries on Android to achieve stable, chainable sandbox-escape capabilities. They will deliver original vulnerabilities, reliable exploit components, and reusable tooling for IPC discovery and instrumentation.

What they look for

Vulnerability Research Chrome Sandbox Escape Android Internals C++ Mojo IPC Exploit Development Binder SELinux Reverse Engineering Fuzzing Patch Analysis Chromium Architecture Kernel Exploitation Instrumentation Variant Analysis

Requirements

Candidates must have demonstrable experience with Chrome/Chromium sandbox escapes and deep knowledge of multi-process architecture and Android internals. Strong practical skills in C++ vulnerability research, Mojo IPC, and Binder are required for this high-difficulty role.

Full description

We are looking for a senior researcher with deep practical experience identifying and exploiting vulnerabilities across Chrome sandbox boundaries on Android.

You should already know how to move from a compromised renderer or low-privilege browser process to a meaningful trust-boundary violation. The goal is stable, chainable sandbox-escape capability on real Android targets.

What you’ll work on

- Renderer-accessible Mojo interfaces, interface brokers and browser-process endpoints.

- GPU, media, network, utility, device and other services reachable from low-privilege Chrome processes.

- Android-specific Chrome integration, including platform bridges, Binder-facing components, permissions and service boundaries.

- Confused-deputy conditions, validation gaps, unsafe deserialisation, lifetime errors, races and state-machine mistakes.

- Cross-process exploitation where asynchronous IPC, handles, shared memory or capability transfer affect reliability.

- End-to-end chains with renderer and Android-kernel researchers when needed.

What you’ll deliver

- Original vulnerabilities that cross a Chrome process, privilege or trust boundary on Android.

- Reliable sandbox-escape exploit components that work under production mitigations.

- Prioritised attack-surface areas that are deemed to be complex enough to contain vulnerabilities.

- Triggers, PoCs, exploitability analysis, target assumptions and complete technical handover.

- Reusable tooling for IPC discovery, Mojo message generation, tracing, instrumentation, coverage and variant analysis.

What we’re looking for

- Demonstrable delivery of Chrome/Chromium sandbox escapes, browser-process vulnerabilities or closely comparable cross-privilege exploitation.

- Deep knowledge of Chromium’s multi-process architecture, sandbox policy and renderer-to-browser trust boundaries.

- Strong practical experience with Mojo IPC, bindings, data pipes, shared memory, interface ownership and message validation.

- Advanced C++ vulnerability-research and exploitation skills in complex multi-process targets.

- Working knowledge of Android internals relevant to Chrome, including application isolation, SELinux domains, Binder and platform services.

- The ability to turn a subtle boundary mistake into a stable result that can be integrated into a wider chain.

- Independent research ownership and a consistent history of finishing high-difficulty work.

Strong signals

- Credited Chrome sandbox escapes or comparable real-world cross-privilege exploit delivery.

- Custom Mojo fuzzers, IPC introspection tools or Chrome instrumentation frameworks.

- Experience chaining renderer compromise through sandbox escape to Android system or kernel impact.

- Research across multiple Android OEMs, chipsets and Chrome branches.

- vulnerabilities found made it to stable/beta releases.

- Strong patch-analysis and variant-hunting results.

How we work

- Fully remote, with high autonomy and close collaboration between browser, platform and kernel specialists.

- We measure progress through technically meaningful, reproducible delivery.

- Public CVEs are not a requirement.