Trending...
- California: Governor Newsom calls for renewing the American Dream for working families at NALEO National Conference - 1085
- California: Governor Newsom secures 13 automakers to offer instant rebates for first-time ZEV buyers
- California: Governor Newsom announces appointments 7.15.2026
Research introduces a deterministic, auditable pipeline that reconstructs control flow and Metro modules, validated by round-trip re-execution across 11 compiler versions.
BROOKLYN, N.Y. - Californer -- Symbiotic Security today announced new research and an open-source tool for deterministic decompilation of Hermes bytecode, the format used by React Native applications in production builds. The decompiler recovers readable JavaScript, including structured control flow, module boundaries, and identifiers, with deterministic output designed for security review.
Find the full research paper here https://hubs.ly/Q04pLtpM0
The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.
"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."
More on The Californer
The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.
About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.
Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.
The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.
Resources
Find the full research paper here https://hubs.ly/Q04pLtpM0
The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.
"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."
More on The Californer
- BROSHIGEEZ Introduces World Hop at Exclusive Los Angeles Music Launch
- Cover Story about Matthew Cossolotto – Author of Harness Your PromisePower -- Published in July 2026 Enterprise World Magazine
- The Swig Company Refinances The Mills Building in San Francisco
- California: Governor Newsom signs executive order strengthening statewide sex trafficking prevention and response
- Are You Maximizing Your Social Media Content?
The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.
About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.
Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.
The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.
Resources
- Research paper download: https://hubs.ly/Q04pLtpM0
- GitHub repository: https://hubs.ly/Q04q0SwP0
Source: Symbiotic Security
Filed Under: Information Technology, Artificial Intelligence
0 Comments
Latest on The Californer
- Snell & Wilmer Recognized as One of the "Best Places to Work" by the Orange County Business Journal
- Snell & Wilmer Counsel Sarah Odegaard Elected to The Priority Center Board of Directors
- Lionheart Holdings and KEO Energy Sign Letter of Intent for Proposed Business Combination
- CFOs Are Solving ASC 842 Lease Accounting Compliance in 2026
- Workplace Injury Reporting Is Getting AI-Assisted in 2026
- Snoop Dogg Could Make $5M Monthly On BTR Music
- Salt Security Introduces the Industry's Largest Policy Library for Agentic AI Governance
- Marcus Christ Announces Singles: "The Hammer Goes Click" and "You Hate Me, I Hate You"
- Fatal FOMO May be Your Last Roll of the Dice
- Book On Shelves Launches to Help Independent and Self-Published Authors Get Their Books
- Relaxation with flow of endorphins, Dr.Abhay Kumar Pati, Physician, Author, California, USA
- FatWealth - Thinking About Becoming a Coach?
- Endorphins: feel good chemicals for Healthy Lifestyle, Dr.Abhay Kumar Pati, Phd, Hayward, CA
- BestHauntedHotels.com Launches America's Premier Haunted Hotel Directory
- Martin A. Sumichrast Joins Hawkeye Systems, Inc. as Chairman of the Board
- Salestrics Unveils Free AI Resume Workspace to Defeat ATS Algorithms Ahead of Major Platform
- SkylieCreates Redefines Meaningful Gifting with New Line of Handcrafted, Curated Gift Boxes
- Allstream Energy Partners Returns as a Media Partner for the 2026 API Inspection & Mechanical Integrity Summit in San Antonio
- NuGuard Launches AI Trust Platform to Close the Behavior Gap and Accelerate Secure Deployments
