Skip to main content

iOS User Space Sandbox Escape - Vulnerability Researcher

RemoteWorldwide
Published
Role
Security
Experience
Senior
Employment
Full-time
Salary not disclosed
Check eligibility

Open to Worldwide. Set where you work from to check your eligibility.

No BS summary

Deeply experienced iOS userspace vulnerability researcher with proven sandbox escapes, privileged-daemon vulnerabilities, or equivalent exploit components. Needs strong iOS exploitation, reverse engineering, Mach/XPC/NSXPC, entitlements, sandboxing, arm64/arm64e, and exploit-chain reliability experience.

Core skills

iOSMachXPC

Required skills

NSXPCObjective-CSwiftCC++ARM64arm64e

What you'll do

  • Privileged iOS daemons, frameworks and services reachable from sandboxed application or browser contexts.
  • Mach, XPC, NSXPC, serialisation and object-bridging boundaries.
  • Memory corruption, logic vulnerabilities, confused-deputy conditions, race conditions and entitlement bypasses.
  • Sandbox profiles, service registration, entitlement checks and cross-process trust relationships.
  • Private-framework and daemon-protocol reverse engineering across iOS releases and arm64e devices.
  • Exploit-chain integration with browser and kernel researchers when required.
  • Original iOS userspace vulnerabilities that cross sandbox, entitlement, process or service boundaries.
  • Reliable sandbox-escape exploit components suitable for integration into broader chains.
  • Prioritised attack-surface maps for privileged services, framework brokers and entitlement-gated functionality.
  • Triggers, PoCs, exploitation strategy, affected-version notes, assumptions and clear technical handover.
  • Reusable tooling for service discovery, message generation, daemon instrumentation, entitlement analysis and variant research.

What they require

  • Proven delivery of iOS sandbox escapes, privileged-daemon vulnerabilities or comparable userspace exploit components.
  • Deep knowledge of iOS process isolation, code signing, entitlements, sandbox profiles and launch/service models.
  • Strong reverse engineering across Objective-C, Swift and C/C++, including private frameworks and stripped binaries.
  • Practical expertise with Mach messaging, XPC/NSXPC, serialisation formats and asynchronous service interactions.
  • Advanced ARM64/arm64e userspace exploitation, including modern heap behaviour, PAC-aware strategies and constrained code execution.
  • The ability to reason about chainability, target variation and reliability rather than stopping at a one-time daemon crash.
  • A consistent history of independently finishing complex research.
  • Public CVEs are useful but not required.

Benefits

  • Fully remote, with high autonomy and direct collaboration with browser and kernel specialists.
Cybersecurity
Salary not disclosed