Chrome Sandbox Escape Android - Vulnerability Researcher

 Posted 2 days ago
     
5-10 years experience
Apply Now

Please mention DailyRemote when applying

AI Summary

The researcher will identify and exploit vulnerabilities across Chrome sandbox boundaries on Android to achieve stable, chainable sandbox-escape capabilities. They will deliver original vulnerabilities, reliable exploit components, and reusable tooling for IPC discovery and instrumentation.

We are looking for a senior researcher with deep practical experience identifying and exploiting vulnerabilities across Chrome sandbox boundaries on Android.

You should already know how to move from a compromised renderer or low-privilege browser process to a meaningful trust-boundary violation. The goal is stable, chainable sandbox-escape capability on real Android targets.

What you’ll work on

- Renderer-accessible Mojo interfaces, interface brokers and browser-process endpoints.

- GPU, media, network, utility, device and other services reachable from low-privilege Chrome processes.

- Android-specific Chrome integration, including platform bridges, Binder-facing components, permissions and service boundaries.

- Confused-deputy conditions, validation gaps, unsafe deserialisation, lifetime errors, races and state-machine mistakes.

- Cross-process exploitation where asynchronous IPC, handles, shared memory or capability transfer affect reliability.

- End-to-end chains with renderer and Android-kernel researchers when needed.

What you’ll deliver

- Original vulnerabilities that cross a Chrome process, privilege or trust boundary on Android.

- Reliable sandbox-escape exploit components that work under production mitigations.

- Prioritised attack-surface areas that are deemed to be complex enough to contain vulnerabilities.

- Triggers, PoCs, exploitability analysis, target assumptions and complete technical handover.

- Reusable tooling for IPC discovery, Mojo message generation, tracing, instrumentation, coverage and variant analysis.

What we’re looking for

- Demonstrable delivery of Chrome/Chromium sandbox escapes, browser-process vulnerabilities or closely comparable cross-privilege exploitation.

- Deep knowledge of Chromium’s multi-process architecture, sandbox policy and renderer-to-browser trust boundaries.

- Strong practical experience with Mojo IPC, bindings, data pipes, shared memory, interface ownership and message validation.

- Advanced C++ vulnerability-research and exploitation skills in complex multi-process targets.

- Working knowledge of Android internals relevant to Chrome, including application isolation, SELinux domains, Binder and platform services.

- The ability to turn a subtle boundary mistake into a stable result that can be integrated into a wider chain.

- Independent research ownership and a consistent history of finishing high-difficulty work.

Strong signals

- Credited Chrome sandbox escapes or comparable real-world cross-privilege exploit delivery.

- Custom Mojo fuzzers, IPC introspection tools or Chrome instrumentation frameworks.

- Experience chaining renderer compromise through sandbox escape to Android system or kernel impact.

- Research across multiple Android OEMs, chipsets and Chrome branches.

- vulnerabilities found made it to stable/beta releases.

- Strong patch-analysis and variant-hunting results.

How we work

- Fully remote, with high autonomy and close collaboration between browser, platform and kernel specialists.

- We measure progress through technically meaningful, reproducible delivery.

- Public CVEs are not a requirement.

Similar Jobs

See all Remote Software Development jobs →

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Software Development

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified