Trending...
- Heritage at South Brunswick Introduces New Ferndale Floorplan: The Largest Single-Family Home Design in the Community - 297
- Spokane: SPD Arrest Level III Registered Sex Offender for Failure to Register - 104
- Spokane Police Respond to Overnight Shooting in Garland District
Research introduces a deterministic, auditable pipeline that reconstructs control flow and Metro modules, validated by round-trip re-execution across 11 compiler versions.
BROOKLYN, N.Y. - Washingtoner -- Symbiotic Security today announced new research and an open-source tool for deterministic decompilation of Hermes bytecode, the format used by React Native applications in production builds. The decompiler recovers readable JavaScript, including structured control flow, module boundaries, and identifiers, with deterministic output designed for security review.
Find the full research paper here https://hubs.ly/Q04pLtpM0
The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.
"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."
More on Washingtoner
The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.
About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.
Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.
The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.
Resources
Find the full research paper here https://hubs.ly/Q04pLtpM0
The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.
"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."
More on Washingtoner
- Phinge & CEO Robert DeMaio Publicly Declare Cash Settlements or Judgments Alone Cannot & Will Not Remedy the Deep Public Harm of Infringing Its IP
- Dana Flanagan Expands the Authority Architect, Bringing a Nontraditional Approach to Executive Authority, Strategic Access and Business Growth
- Phinge's Netverse: Reclaiming the Digital Frontier For Everyone Through CEO Robert DeMaio's Vision of a True App-less, User Data Sovereign World
- DuraFast Label Company Launches Seiko SLP850 2" Thermal Printer with Free Label Promotion
- Scientific Figure Releases Free Layout Template Libraries for Graphical Abstracts and Research Posters
The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.
About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.
Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.
The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.
Resources
- Research paper download: https://hubs.ly/Q04pLtpM0
- GitHub repository: https://hubs.ly/Q04q0SwP0
Source: Symbiotic Security
0 Comments
Latest on Washingtoner
- Covington Makers Market Returns Sept. 12 with Local Makers, Artists, Small Businesses & Food Vendors
- Fit Body Boot Camp Launches Nationwide 'Fit Body Forever' Workshops to Help Adults 60+ Rebuild Strength and Prevent Falls
- Canadian Aerospace Defence Talent Expo (CADTE) Launches National TalentThread Initiative to Strengthen Canada's Future Workforce
- 5.6 Million EUR in Q1 Project Awards for Integrated IoT Solutions / Data Analytics Subsidiary of Smart City Developer: Affluence (Stock Symbol: AFFU)
- Merger Advancement For Embodied AI Co in Robotic Systems Serving High Value Hospitality, Gaming & Real Estate Sectors: MBody AI Corp. (NAS DAQ: MBAI)
- Hollywood In Pixels Announces Honorees for The 9th Silver PIXel Awards
- New Research Finds a Good Deal Is All It Takes to Get Americans Booking a Last-Minute Vacation — and Most Already Have One on Their Mind
- GitKraken Introduces GitLens 19, Bringing Human and AI Workflows Together in One Workbench
- LĪNA Universal Balm Nominated for "Best Clean Skincare Product" at CertClean Beauty Awards
- Spokane: SPD Arrest Level III Registered Sex Offender for Failure to Register
- SPD Detectives Investigating Suspicious Deaths in Northeast Spokane
- Bronze Stevie Award Recognizes Satyadhar Joshi for AI Research and Public Policy Engagement
- synseer Nominated for Best Startup in 2026 Prix Galien USA Awards Following Record Breaking Applicant Pool
- Leading PDR Training Courses in Canada: Learn Paintless Dent Repair with PDR Academy & Tint Academy
- Tacoma: Update Second Homicide Arrest – 2100 block of N 30th St
- Move in this Fall! New Released Quick Move-In Townhomes at Heritage at South Brunswick with Limited-Time Incentives
- Statement by Tacoma City Council Member John Hines on Advancing a Regional Effort to Address Animal Overpopulation
- Crossroads4Hope Marks 25 Years Ensuring No One Faces Cancer Alone At its Inspiring Hope Gala
- Q1 2026 Arizona Technology Industry Impact Report Recaps Advanced Manufacturing Growth, High-Value Jobs and Workforce Investment
- Spokane Police Respond to Midday Shooting on STA Bus
