Trending...
- Eddy Corp and SMAART POWER LLC Announce Strategic Teaming Agreement to Accelerate Microgrid and Distributed Energy Deployments - 398
- City of Long Beach Opens Applications for Third Cohort of Long Beach Fire Corps Program - 121
- Trick-or-Treat Along the El Dorado Nature Center Trails During Howl-o-ween Festival, Hosted by Long Beach Parks, Recreation and Marine - 119
Research introduces a deterministic, auditable pipeline that reconstructs control flow and Metro modules, validated by round-trip re-execution across 11 compiler versions.
BROOKLYN, N.Y. - Californer -- Symbiotic Security today announced new research and an open-source tool for deterministic decompilation of Hermes bytecode, the format used by React Native applications in production builds. The decompiler recovers readable JavaScript, including structured control flow, module boundaries, and identifiers, with deterministic output designed for security review.
Find the full research paper here https://hubs.ly/Q04pLtpM0
The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.
"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."
More on The Californer
The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.
About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.
Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.
The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.
Resources
Find the full research paper here https://hubs.ly/Q04pLtpM0
The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.
"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."
More on The Californer
- California: Governor Newsom takes action to help lower prices amid Trump's nationwide gas and diesel price spike
- Home Prices Fall as Sales RiseāMortgage Rates Jump Back Above 7%
- California: Governor Newsom signs legislation supporting veterans, servicemembers
- Governor Newsom signs legislation creating non-UPF label, other health bills advancing California's nation-leading healthcare strategy
- New Book: Off The Edge: Relieving Everyday Anxiety
The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.
About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.
Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.
The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.
Resources
- Research paper download: https://hubs.ly/Q04pLtpM0
- GitHub repository: https://hubs.ly/Q04q0SwP0
Source: Symbiotic Security
Filed Under: Information Technology, Artificial Intelligence
0 Comments
Latest on The Californer
- Decode Digital Works to Participate in California Technology Summit in Anaheim
- Moorpark College to Premiere New Temporary Amphitheater with Free Concert
- Derek Cook's Roofing Encourages Homeowners to Prepare for Fall Weather
- ACTIQO 3.0 Connects Google and Apple Calendars to Help Families Manage the Work Behind Youth Sports
- Boston Industrial Solutions Expands Product Offering with Pad Printing Pads and Silicone for Custom Pad Manufacturing
- Rodeo FX Originals Appoints Yvann Thibaudeau Head of Development & IP
- ShortsTV & NFDC Announce Oscar Qualifying Theatrical Run for The Paper Sky at CINELOUNGEĀ® TIBURON
- AquaMesh Builds Physical AI to Help Industrial Facilities Catch Costly Problems Early
- Jedi Survivor's D.C. Douglas Returns to Star Wars in Critically Acclaimed Zero Company
- Albert Wesker Voted #1 Resident Evil Villain of All Time in Capcom's Official 30th Anniversary Poll
- Pervaziv AI joins OpenAI's Call for Collective Action on Cyber Defense
- Phoenix 5/7 Emerges as a Genre-Fluid Artist Collective
- California: Governor Newsom signs bills to strengthen accountability for cold storage facilities, following emergency in Boyle Heights
- Massage Revolution Expands to Santa Monica With New Wilshire Boulevard Location
- Liposomal Procedure for Ayurvedic herbal products, Dr.Abhay Kumar Pati, Hayward, CA USA
- "Warrior Defined" Event Brings Men Together in Charlotte, With Calls for Events Across the U.S
- Legislators, survivors and gun-safety advocates support Governor Newsom's signature on California's latest gun-safety package
- Governor Newsom signs new laws expanding California's nation-leading reproductive freedom and care
- Luna Select Market Refreshes Its Catalog With Practical Home, Kitchen and Smart-Home Finds, Plus Free U.S. Shipping
- Author Steve Ulrich Releases Perception: Seeing Beyond What First Appears
