Trending...
- No Sugar Baker Continues National Growth with Seattle Market Expansion Across Washington, Idaho, and Alaska - 140
- 5X Gross Margin Improvement to Beat EPS Consensus; $54.6 Million 10-Year Contract Award Puts Cybersecurity Leader on Path to a $30 Million Run Rate - 140
- Free Commercial Glass Estimating and Code Compliance Tools Launched by Landmark Construction - The Leading Glass Company in Los Angeles - 139
Research introduces a deterministic, auditable pipeline that reconstructs control flow and Metro modules, validated by round-trip re-execution across 11 compiler versions.
BROOKLYN, N.Y. - Michimich -- Symbiotic Security today announced new research and an open-source tool for deterministic decompilation of Hermes bytecode, the format used by React Native applications in production builds. The decompiler recovers readable JavaScript, including structured control flow, module boundaries, and identifiers, with deterministic output designed for security review.
Find the full research paper here https://hubs.ly/Q04pLtpM0
The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.
"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."
More on Michimich.com
The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.
About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.
Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.
The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.
Resources
Find the full research paper here https://hubs.ly/Q04pLtpM0
The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.
"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."
More on Michimich.com
- Where Do Missouri Plane Crashes Really Happen? Not Where You'd Think
- LCC Asia Pacific Sponsors CubeSatPlus 2026 at UNSW Sydney
- Ann Arbor Area Community Foundation's Annual Community Meeting Returns September 15!
- Real Estate Syndication Attorney Tilden Moschetti Releases The Real Estate Private Equity Blueprint
- 5X Gross Margin Improvement to Beat EPS Consensus; $54.6 Million 10-Year Contract Award Puts Cybersecurity Leader on Path to a $30 Million Run Rate
The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.
About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.
Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.
The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.
Resources
- Research paper download: https://hubs.ly/Q04pLtpM0
- GitHub repository: https://hubs.ly/Q04q0SwP0
Source: Symbiotic Security
0 Comments
Latest on Michimich.com
- Paula Josephine Sadler Releases "Imagine" on 24th Anniversary of Sobriety
- Ritz-Carlton Residences Houston Generates Strong Early New Construction Sales at 2120 Post Oak Blvd
- No Sugar Baker Continues National Growth with Seattle Market Expansion Across Washington, Idaho, and Alaska
- Why Most Manager Training Doesn't Work, According to a Michigan Founder
- The Refugee Archive Launches Campaign to Preserve 21 Female-Headed Household Oral Histories in Rebel-Controlled Goma
- The Championship Lives On: Own a Piece of Michigan Basketball History
- Space Ambitions Expanding as New Testing Builds on NASA Results and Targets MEO, GEO and Next-Generation Orbital Markets: Ascent Solar Technologies
- FDA Path Clears, Manufacturing Ramps Up + $22.3 Million Strengthens the Balance Sheet; Inflection Point for NRx Pharmaceuticals (N A S D A Q: NRXP)
- Buy Retatrutide Research Peptide: Why Reta Is Getting So Much Attention
- San Diego Attorney Anthony Z. Vargas Narrows Practice to Employment Law, Representing Employees Only
- PSED Attorney Charles Drabik Named Co-Chair of WCBA Probate & Estate Planning Section
- Pear Sperling Eggan & Daniels, P.C. Attorneys Recognized as 2026 Super Lawyers
- Solid Earth Introduces RealtyID, a Universal Identity Spine for the Real Estate Industry
- BlazeHive's AI SEO Agent Outranks Human Writers on 500+ Google Top-3 Results in 5 Months, on Autopilot
- Phinge Exposes Massive AI Security Risks, Claiming Its Patented Hardware-Verified Architecture Is The Only Safeguard Against Surveillance Capitalism
- Phinge & CEO Robert DeMaio Publicly Declare Cash Settlements or Judgments Alone Cannot & Will Not Remedy the Deep Public Harm of Infringing Its IP
- Dana Flanagan Expands the Authority Architect, Bringing a Nontraditional Approach to Executive Authority, Strategic Access and Business Growth
- Phinge's Netverse: Reclaiming the Digital Frontier For Everyone Through CEO Robert DeMaio's Vision of a True App-less, User Data Sovereign World
- DuraFast Label Company Launches Seiko SLP850 2" Thermal Printer with Free Label Promotion
- Gratitude Geek Wins Two 2026 Marketing Podcast Network Awards
