Chrome Sandbox Android - Vulnerability Researcher
Listed on 2026-09-27
-
Security
Cybersecurity
We are looking for a senior researcher with deep practical experience identifying and exploiting vulnerabilities across Chrome sandbox boundaries on Android.
You should already know how to move from a compromised renderer or low-privilege browser process to a meaningful trust-boundary violation. The goal is stable, chainable sandbox-escape capability on real Android targets.
What you’ll work onRenderer-accessible Mojo interfaces, interface brokers and browser-process endpoints.
GPU, media, network, utility, device and other services reachable from low-privilege Chrome processes.
Android-specific Chrome integration, including platform bridges, Binder-facing components, permissions and service boundaries.
Confused-deputy conditions, validation gaps, unsafe deserialisation, lifetime errors, races and state-machine mistakes.
Cross-process exploitation where asynchronous IPC, handles, shared memory or capability transfer affect reliability.
End-to-end chains with renderer and Android-kernel researchers when needed.
Original vulnerabilities that cross a Chrome process, privilege or trust boundary on Android.
Reliable sandbox-escape exploit components that work under production mitigations.
Prioritised attack-surface areas that are deemed to be complex enough to contain vulnerabilities.
Triggers, PoCs, exploitability analysis, target assumptions and complete technical handover.
Reusable tooling for IPC discovery, Mojo message generation, tracing, instrumentation, coverage and variant analysis.
Demonstrable delivery of Chrome/Chromium sandbox escapes, browser-process vulnerabilities or closely comparable cross-privilege exploitation.
Deep knowledge of Chromium’s multi-process architecture, sandbox policy and renderer-to-browser trust boundaries.
Strong practical experience with Mojo IPC, bindings, data pipes, shared memory, interface ownership and message validation.
Advanced C++ vulnerability-research and exploitation skills in complex multi-process targets.
Working knowledge of Android internals relevant to Chrome, including application isolation, SELinux domains, Binder and platform services.
The ability to turn a subtle boundary mistake into a stable result that can be integrated into a wider chain.
Independent research ownership and a consistent history of finishing high-difficulty work.
Credited Chrome sandbox escapes or comparable real-world cross-privilege exploit delivery.
Custom Mojo fuzzers, IPC introspection tools or Chrome instrumentation frameworks.
Experience chaining renderer compromise through sandbox escape to Android system or kernel impact.
Research across multiple Android OEMs, chipsets and Chrome branches.
vulnerabilities found made it to stable/beta releases.
Strong patch-analysis and variant-hunting results.
Fully remote, with high autonomy and close collaboration between browser, platform and kernel specialists.
We measure progress through technically meaningful, reproducible delivery.
Public CVEs are not a requirement.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).