Trending...
- Akiti Series Lands on Back-to-School Lists - 244
- Vallejo Home Prices Are Down—"The Price is Right" is Not Just a Game Show - 103
- California: Governor Newsom invites President Trump to deliver overdue wildfire recovery funding during Los Angeles visit - 102
Research introduces a deterministic, auditable pipeline that reconstructs control flow and Metro modules, validated by round-trip re-execution across 11 compiler versions.
BROOKLYN, N.Y. - Californer -- Symbiotic Security today announced new research and an open-source tool for deterministic decompilation of Hermes bytecode, the format used by React Native applications in production builds. The decompiler recovers readable JavaScript, including structured control flow, module boundaries, and identifiers, with deterministic output designed for security review.
Find the full research paper here https://hubs.ly/Q04pLtpM0
The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.
"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."
More on The Californer
The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.
About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.
Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.
The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.
Resources
Find the full research paper here https://hubs.ly/Q04pLtpM0
The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.
"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."
More on The Californer
- Audi Lemon Law Attorney in Los Angeles County
- Leather Repair World Expands to San Francisco With Professional Mobile Restoration Services
- Awepra Launches Free OutRun Classic Sega Arcade Game Online — No Ads, No Download Required
- Rabbi Michael "Moshe" Rothschild (#ViralRabbi) to Join LifePodcast for Special Series on Futurism
- Bellhaven & Co., A Pet Lifestyle Brand Inspired by a Rescue Dog Named Bella
The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.
About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.
Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.
The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.
Resources
- Research paper download: https://hubs.ly/Q04pLtpM0
- GitHub repository: https://hubs.ly/Q04q0SwP0
Source: Symbiotic Security
Filed Under: Information Technology, Artificial Intelligence
0 Comments
Latest on The Californer
- California: Governor Newsom announces judicial appointments
- Pervaziv AI Debuts Cortex Router as the Eighth Model in Its Specialized AI Ensemble
- Governor Newsom announces $3,500 instant rebates now available for Californians buying their first zero-emission vehicle
- Bestselling Author Unlocks THE CAT SECRET: The Hidden Soul Pur(r)pose and Cosmic Origins of Cats
- The City's Most Elegant Open-Air Dinner Party Returns September 12, 2026
- Local groomer Katlin Molina earns Fear Free Groomer Certification
- Registration for Long Beach's Free After School Program Begins Aug. 10
- IEI's iVEC Edge Server Cuts AMR Fleet Management Deployment Cost
- Backtested Strategies Announces BTS Strength Zones — Dow-65 Stocks Backtest Results
- A New Name Enters the Packaging World: The Luxury Packaging USA Launches in San Mateo, California
- California: Governor Newsom honors commitment to wildlife protection and public safety with 36 new law enforcement officers
- FDA Clears Major Regulatory Hurdle as Preservative-Free Ketamine Program Moves Within Reach of Commercialization: NRx Pharmaceuticals: (NAS DAQ: NRXP)
- Autonomous Robotics Platform Expansion as Public Market Debut is Very Close: MBody AI Corp. (N A S D A Q: MBAI)
- Atlas Elite Entertainment Launches Monthly Press Publication Celebrating Excellence, Entertainment
- Jon Robert Quinn Releases New Instrumental Rock Album "Time" with Music from his High Rise Films
- California: Governor Newsom proclaims State of Emergency in Calaveras County for the Gann Fire response
- California: Governor Newsom announces appointments
- Ashley Clarice Stars in Upcoming Drama Thriller Premiering August 24 on Amazon Prime and Apple TV
- California: Governor Newsom signs legislation 8.6.2026
- Next-Gen AI-Native Auto Repair & Fleet Platform Launches, Onboarding Dozens of Shops
