iOS User Space Sandbox Escape - Vulnerability Researcher
Trenchant
IT Services and IT Consulting · 2-10 employees
About the role
The researcher will identify and exploit vulnerabilities in iOS userspace, focusing on privileged daemons, frameworks, and service boundaries. They will deliver original exploit components, attack-surface maps, and reusable tooling to support broader security research chains.
What they look for
Requirements
Candidates must have a proven track record of delivering iOS sandbox escapes and privileged-daemon vulnerabilities. Strong expertise in reverse engineering, ARM64 exploitation, and deep knowledge of iOS process isolation and entitlement models is required.
Full description
We are looking for a deeply experienced iOS userspace researcher who has already delivered sandbox escapes, privileged-daemon vulnerabilities or equivalent exploit components.
The work is focused on real trust boundaries exposed through Mach, XPC, private frameworks, privileged services and entitlement-gated functionality. This is not an application-security or jailbreak-usage role.
What you’ll work on
- Privileged iOS daemons, frameworks and services reachable from sandboxed application or browser contexts.
- Mach, XPC, NSXPC, serialisation and object-bridging boundaries.
- Memory corruption, logic vulnerabilities, confused-deputy conditions, race conditions and entitlement bypasses.
- Sandbox profiles, service registration, entitlement checks and cross-process trust relationships.
- Private-framework and daemon-protocol reverse engineering across iOS releases and arm64e devices.
- Exploit-chain integration with browser and kernel researchers when required.
What you’ll deliver
- Original iOS userspace vulnerabilities that cross sandbox, entitlement, process or service boundaries.
- Reliable sandbox-escape exploit components suitable for integration into broader chains.
- Prioritised attack-surface maps for privileged services, framework brokers and entitlement-gated functionality.
- Triggers, PoCs, exploitation strategy, affected-version notes, assumptions and clear technical handover.
- Reusable tooling for service discovery, message generation, daemon instrumentation, entitlement analysis and variant research.
What we’re looking for
- Proven delivery of iOS sandbox escapes, privileged-daemon vulnerabilities or comparable userspace exploit components.
- Deep knowledge of iOS process isolation, code signing, entitlements, sandbox profiles and launch/service models.
- Strong reverse engineering across Objective-C, Swift and C/C++, including private frameworks and stripped binaries.
- Practical expertise with Mach messaging, XPC/NSXPC, serialisation formats and asynchronous service interactions.
- Advanced ARM64/arm64e userspace exploitation, including modern heap behaviour, PAC-aware strategies and constrained code execution.
- The ability to reason about chainability, target variation and reliability rather than stopping at a one-time daemon crash.
- A consistent history of independently finishing complex research.
Strong signals
- Public iOS security credits, jailbreak-chain research or comparable exploit-chain delivery.
- Experience chaining browser compromise into an iOS userspace sandbox escape.
- Custom XPC/Mach fuzzing, service-introspection or firmware-analysis tooling.
- Research across multiple major iOS generations and arm64e hardware families.
- Strong patch-diffing and variant-hunting results.
How we work
- Fully remote, with high autonomy and direct collaboration with browser and kernel specialists.
- We value technically meaningful delivery, clean handover and reproducibility over activity metrics or polished theatre.
- Public CVEs are useful but not required.