Trending...
- For Labor Day: Check out a poem about Labor and Manufacturing called "It used to be Made in America" - 198
- California prioritized fighting organized retail theft, those results are paying off with 36,000 arrests and $293 million in stolen goods recovered - 105
- California and the Australian state of Queensland ink new partnership to accelerate climate resilience, agricultural technology, and innovation - 103
Research introduces a deterministic, auditable pipeline that reconstructs control flow and Metro modules, validated by round-trip re-execution across 11 compiler versions.
BROOKLYN, N.Y. - Californer -- Symbiotic Security today announced new research and an open-source tool for deterministic decompilation of Hermes bytecode, the format used by React Native applications in production builds. The decompiler recovers readable JavaScript, including structured control flow, module boundaries, and identifiers, with deterministic output designed for security review.
Find the full research paper here https://hubs.ly/Q04pLtpM0
The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.
"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."
More on The Californer
The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.
About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.
Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.
The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.
Resources
Find the full research paper here https://hubs.ly/Q04pLtpM0
The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.
"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."
More on The Californer
- Five International Travel Deals for Seniors Start at Just $995
- Interpreters Unlimited Recognized Among San Diego's 2026 Companies That Care
- IEI Launches Itten-E315, a 31.5-Inch Six-Color ePaper Display
- Impact & Influence April 2026: Joel Rodriguez Tirado on Renewal,Growth & Uncomfortable Conversations
- Franchise Operators Are Standardizing Compliance Across Every Location in 2026
The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.
About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.
Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.
The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.
Resources
- Research paper download: https://hubs.ly/Q04pLtpM0
- GitHub repository: https://hubs.ly/Q04q0SwP0
Source: Symbiotic Security
Filed Under: Information Technology, Artificial Intelligence
0 Comments
Latest on The Californer
- xBxBio Advances Connected Cardiovascular Intelligence With Chapter 2 Release
- Share your workplace safety solutions at 2027 Applied Ergonomics Conference
- Parents No Longer Have to Wait 3 Weeks for a Sleep Consultant: Nora Talks Tonight, Stays for 5 Days, Costs $89
- May The Worst Team Win! Loserball Kicks Off Another NFL Season of Hilarious Mayhem
- Wehb.pro Launches $99 AI Website Builder With No Subscription or Platform Lock-In
- Top 10 AI Trading Robots Beat Market targeting High-Margin Stocks at 155% Annualized Return for Retail Investors (NVDA, USAR)
- Black Women Living With, and Impacted by, HIV Express Gratitude, Grief, Joy, and Resilience
- MainConcept Easy Video API Extends Full Transcoding to Arm and NETINT VPUs
- Boost Board Gives Daily Visibility to Fundraising Campaigns Stuck at Zero
- Hazel-E Celebrates the Premiere of "Keeping Up With Hazel-E" on Wave TV Network
- Talaria E-bike China Source Cuts Talaria Sting MX5 Pro Pricing by $700
- Disruptor Creations Options Untitled Feature Film Written by David Krumholtz and Johnny Markows
- Skin Health Expert and Nurse Practitioner Blossom Inuenwi Launches 'The Glow Brief' Podcast
- AristoPup Grooming Launches "Fresh Start Grooming Days" to Help Palm Springs Animal Shelter Dogs
- New Edition of Bestselling Book Reveals How Consciousness Shapes Your Genes
- P&C Insurers -- Meet Me at ITC Vegas
- Happy Labor Day! California is the #1 for state for workers, #1 economy in the nation
- California: Governor Newsom proclaims Labor Day
- John Pape Releases Christian Single "The Road," Inspired by the Romans Road
- Cruxy shortlisted for two Private Equity Wire® US Awards 2026: Advisory Firm of the Year (Overall) & Value Creation Consulting Firm of the Year
