Trending...
- Allstream Energy Partners Returns as a Media Partner for the 2026 API Inspection & Mechanical Integrity Summit in San Antonio - 118
- Secure Mount Awarded VA Federal Supply Schedule Contract, Expanding Access to Innovative Mounting Solutions for Government Healthcare Facilities - 105
- Award-Winning Heritage at South Brunswick Continues to Thrive as One of New Jersey's Premier New Home Communities
Research introduces a deterministic, auditable pipeline that reconstructs control flow and Metro modules, validated by round-trip re-execution across 11 compiler versions.
BROOKLYN, N.Y. - Michimich -- Symbiotic Security today announced new research and an open-source tool for deterministic decompilation of Hermes bytecode, the format used by React Native applications in production builds. The decompiler recovers readable JavaScript, including structured control flow, module boundaries, and identifiers, with deterministic output designed for security review.
Find the full research paper here https://hubs.ly/Q04pLtpM0
The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.
"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."
More on Michimich.com
The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.
About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.
Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.
The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.
Resources
Find the full research paper here https://hubs.ly/Q04pLtpM0
The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.
"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."
More on Michimich.com
- Hillside Terrace Highlights the Importance of Community in Senior Living
- ACTIQO Receives Apple App Store Approval Ahead of Back-to-School Launch
- Marcus Christ Announces Singles: "The Hammer Goes Click" and "You Hate Me, I Hate You"
- Fatal FOMO May be Your Last Roll of the Dice
- Martin A. Sumichrast Joins Hawkeye Systems, Inc. as Chairman of the Board
The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.
About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.
Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.
The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.
Resources
- Research paper download: https://hubs.ly/Q04pLtpM0
- GitHub repository: https://hubs.ly/Q04q0SwP0
Source: Symbiotic Security
0 Comments
Latest on Michimich.com
- PokerStars & Ladbrokes veteran buys into Finnish news media Rahapelisanomat
- Former Judge Chris Oldner Honored as Best Lawyer by "D Magazine" for 6th Straight Year
- Roofman USA Highlights Key Factors Homeowners Should Consider When Choosing a Roofing Contractor
- JMAC Highlights the Core Principles of Iaido and the Benefits of Traditional Japanese Sword Training
- CMR Mechanical Encourages Homeowners to Prep for Summer Power Outages With Reliable Generators
- Compressed Gas Technologies Highlights the Importance of Nitrogen in Additive Manufacturing
- Missouri Hemp Businesses File Federal Lawsuit Challenging HB 2641
- AdviCoach of Southeast Michigan Rebrands to AdviCoach Business Coaching
- Boston Industrial Solutions Launches New Citrine® SA1-370 Silicone Glue for Permanent Adhesion
- Northeast Airlines Launches New Asset Management Group
- The best view of your business isn't from your desk
- AI Visibility Labs LLC - Dallas Texas - July 16 2026
- NextBoat's AI-Powered Marine Marketplace Gains Momentum as Record Growth Signals an Inflection Point for Investors (N Y S E American: NXB)
- Stepping Off the Grid: Savista Retreat Announces New Experiential Packages in Jaipur for Travellers
- Where Is Your Faith The Movie and Sountrack
- Bynn Intelligence Ranks #1 in NIST Child Online Safety Evaluation for Ages 13–16
- Rev-O-Box™ Launches Reversible Shipping Box That Instantly Becomes a Premium Gift Box
- Las Vegas Estate Firm Ghandi Deeter Blackham Offers Insight on Tony Hsieh's Contested $500 Million Will
- CCHR: Congressional Hearing Revives Lessons from MKULTRA Era – Why Past Psychiatric Human Rights Abuses Demand Vigilance Today
- Pacto Medical Wins Red Dot Design Concept Award 2026 for Slimshot® Compact Prefilled Syringe
