Trending...
- Tacoma: Deputy Mayor Joe Bushnell Seeks Community Feedback on $20 Per Hour Minimum Wage Proposal
- Spokane: Flags Lowered for Senator Lindsey Graham
- City of Tacoma to Collect Community Ideas for District 5 Project
Research introduces a deterministic, auditable pipeline that reconstructs control flow and Metro modules, validated by round-trip re-execution across 11 compiler versions.
BROOKLYN, N.Y. - Washingtoner -- Symbiotic Security today announced new research and an open-source tool for deterministic decompilation of Hermes bytecode, the format used by React Native applications in production builds. The decompiler recovers readable JavaScript, including structured control flow, module boundaries, and identifiers, with deterministic output designed for security review.
Find the full research paper here https://hubs.ly/Q04pLtpM0
The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.
"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."
More on Washingtoner
The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.
About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.
Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.
The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.
Resources
Find the full research paper here https://hubs.ly/Q04pLtpM0
The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.
"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."
More on Washingtoner
- A human conducted an orchestra of AI models. They improvised — and chose raga
- Martin A. Sumichrast Joins Hawkeye Systems, Inc. as Chairman of the Board
- Allstream Energy Partners Returns as a Media Partner for the 2026 API Inspection & Mechanical Integrity Summit in San Antonio
- Spokane: Public Service Announcement
- Spokane: SPD Seek Community Assistance in Locating Missing 13-year-old
The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.
About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.
Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.
The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.
Resources
- Research paper download: https://hubs.ly/Q04pLtpM0
- GitHub repository: https://hubs.ly/Q04q0SwP0
Source: Symbiotic Security
0 Comments
Latest on Washingtoner
- Northeast Airlines Launches New Asset Management Group
- AI Visibility Labs LLC - Dallas Texas - July 16 2026
- NextBoat's AI-Powered Marine Marketplace Gains Momentum as Record Growth Signals an Inflection Point for Investors (N Y S E American: NXB)
- DBF Viewer 2000 v9.25 Adds Command-Line Index Tag Removal
- Stepping Off the Grid: Savista Retreat Announces New Experiential Packages in Jaipur for Travellers
- Where Is Your Faith The Movie and Sountrack
- Bynn Intelligence Ranks #1 in NIST Child Online Safety Evaluation for Ages 13–16
- Rev-O-Box™ Launches Reversible Shipping Box That Instantly Becomes a Premium Gift Box
- Spokane: Flags Lowered for Senator Lindsey Graham
- Las Vegas Estate Firm Ghandi Deeter Blackham Offers Insight on Tony Hsieh's Contested $500 Million Will
- CCHR: Congressional Hearing Revives Lessons from MKULTRA Era – Why Past Psychiatric Human Rights Abuses Demand Vigilance Today
- City of Tacoma to Collect Community Ideas for District 5 Project
- Pacto Medical Wins Red Dot Design Concept Award 2026 for Slimshot® Compact Prefilled Syringe
- Heritage at Manalapan Introduces Luxury Single-Family Homes with Exceptional Value in One of Monmouth County's Most Desirable Locations
- Achugogo: Tale of the Spring Chaser Wins Inaugural TCCF Prize at Mifa Pitches, the Industry Market of the Annecy International Animation Film Festival
- Tacoma Police Department to Swear in New K-9 Teams
- Everything Policy Launches Madison, an AI Tool That Makes Legislation Readable for Students and Citizens
- Is the Market Missing One of the Most Undervalued Cybersecurity Companies on the Stock Market? Cycurion, Inc. (N A S D A Q: CYCU):
- Billion-Dollar Scale Global Technology Powerhouse Being Built with Expanding Government Contracts: Circle8 Group (N A S D A Q: CIRC)
- Tacoma City Council Adopts Stronger Environmental Protections
