Trending...
- UK Financial Ltd Verifies Maya Preferred PRA Circulating Supply, Proving Its Eight-Year Promise of Under 1M Tokens After Chainlink Labs Agreement - 114
- Omnitronics launches Ecosystem Health Dashboard to enable proactive monitoring across dispatch environments - 109
- New Research Identifies "The Great Junk Transfer": 49% of Americans Would Rather Inherit Nothing Than Sort Through a Relative's Belongings
Research introduces a deterministic, auditable pipeline that reconstructs control flow and Metro modules, validated by round-trip re-execution across 11 compiler versions.
BROOKLYN, N.Y. - Michimich -- Symbiotic Security today announced new research and an open-source tool for deterministic decompilation of Hermes bytecode, the format used by React Native applications in production builds. The decompiler recovers readable JavaScript, including structured control flow, module boundaries, and identifiers, with deterministic output designed for security review.
Find the full research paper here https://hubs.ly/Q04pLtpM0
The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.
"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."
More on Michimich.com
The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.
About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.
Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.
The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.
Resources
Find the full research paper here https://hubs.ly/Q04pLtpM0
The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.
"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."
More on Michimich.com
- CGT Explains How a Nitrogen Generator for Laser Cutting Improves More than Productivity
- Mussio Painting Highlights the Importance of Annual Cleaning and Routine Inspections
- Autonomous Robotics Platform Expansion as Public Market Debut is Very Close: MBody AI Corp. (N A S D A Q: MBAI)
- Loud! OOH calls for prize draw advertising standards as £1.3bn category moves outdoors
- Retiree Returns to the Golf Course After Finding Relief from Debilitating Golf Injuries at Macomb Township Chiropractic
The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.
About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.
Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.
The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.
Resources
- Research paper download: https://hubs.ly/Q04pLtpM0
- GitHub repository: https://hubs.ly/Q04q0SwP0
Source: Symbiotic Security
0 Comments
Latest on Michimich.com
- AdviCoach Business Coaching Helps Owners Move Forward With a Trusted Advisor in Their Corner
- Opteamix welcomes Girish Ramachandra to its leadership team as Senior Vice President of Client Services
- Silicon Box Ships 500M Units at High Yield, Expands Production Capacity for Panel-Level Packaging
- Ann Arbor Chiropractor Helps Treat Stubborn Chronic Pain
- Handeholder Products Goes from Custom iPad Holder to Full Line of Holding Solutions
- Michigan Dock Designer & Manufacturer Gives Tips for Making Your Dock Dog-Friendly
- Why Baton Rouge's Humid Climate Can Contribute to Carpenter Ant Damage — J&J Exterminating Explains How to Protect Your Home
- RPR Promotes Emily Line to Chief Strategy Officer and Janine Sieja to Chief Product Officer
- Expanding Beyond Space as New Drone Market Opportunities Accelerate Growth: Ascent Solar Technologies (N A S D A Q: ASTI)
- Lauren Merrell, Dale Sorensen Real Estate, announces price improvement for an extraordinary island retreat
- BasBlue Hosts Bold Women Health Day Summit, Presented by Henry Ford Health, Aug. 15 in Detroit
- Portalz Publishes FES World First Architecture Introducing a New Cryptographic Platform
- Cellofest Brings Free Cello Concerts and Community Events to Bethany Beach August 5–16
- Blue Sky Capital Strategies, LLC awarded Leasing and Financial Services agreement with Premier Inc
- Michael M. Thomas Expands Executive Leadership Across Central India Outreach and Royal Trinity School
- Northeast Airlines and Travel, Inc. Initiates FAA Part 121 Certification for Boeing 737-800 Freighter Cargo Operations
- Walker's Realty and North Jersey Properties Introduce Extraordinary Luxury Estate for Rent in West Orange, New Jersey
- Extreme Heat Strains Home Appliances: Appliance EMT Offers "Summer Rescue" Relief
- Independent West Texas Metal Multi-Instrumentalist & Producer. "MAD CHAD™" Russell Surpasses 1.9 Million Project Interactions Via DFGS Productions
- No Download Needed: Goosechase Adds Browser Play to Every Experience
