Trending...
- ANSI BSR Upholds Appeal of AFDE Member Andrew Sulner, MSFS, JD, finding the AAFS Academy Standards Board (ASB) Violated ANSI Essential Requirements
- RAS AP Consulting Spotlights Managed AP Governance™ at Esker All Access
- New Analysis Details Three Converging Forces in AI and Workforce Policy Behind a $37 Billion GDP Reduction
Research introduces a deterministic, auditable pipeline that reconstructs control flow and Metro modules, validated by round-trip re-execution across 11 compiler versions.
BROOKLYN, N.Y. - PrAtlas -- Symbiotic Security today announced new research and an open-source tool for deterministic decompilation of Hermes bytecode, the format used by React Native applications in production builds. The decompiler recovers readable JavaScript, including structured control flow, module boundaries, and identifiers, with deterministic output designed for security review.
Find the full research paper here https://hubs.ly/Q04pLtpM0
The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.
"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."
More on PrAtlas
The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.
About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.
Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.
The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.
Resources
Find the full research paper here https://hubs.ly/Q04pLtpM0
The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.
"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."
More on PrAtlas
- Sales Blueprint Architect Launches, Helping Sales Professionals, Business Owners, and Consultants Close More Business With AI
- Parksy (parksy.com) Tackles the Most Common Parking Problem Nobody Talks About: Finding the Car Again
- 3ptechies Partners with Coolmuster to Give Away Data Recovery Software Licenses
- INAD Warriors' 4th Annual "Dancing with the INAD Stars" Gala
- DAZN Review 2026: Streaming Price Worth It?
The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.
About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.
Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.
The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.
Resources
- Research paper download: https://hubs.ly/Q04pLtpM0
- GitHub repository: https://hubs.ly/Q04q0SwP0
Source: Symbiotic Security
0 Comments
Latest on PrAtlas
- Supreme Garage Door Repair Redirects Marketing Dollars Into North Texas Communities
- RAS AP Consulting Spotlights Managed AP Governance™ at Esker All Access
- ANSI BSR Upholds Appeal of AFDE Member Andrew Sulner, MSFS, JD, finding the AAFS Academy Standards Board (ASB) Violated ANSI Essential Requirements
- Kentucky's Plane Crash Data Lands Far from the State's Busiest Airports
- StockResearch AI Initiates Coverage on Apple (AAPL) With New Report Examining Valuation, AI Strategy and Future Growth
- Netberg Announces the Aurora X2 Switch Series, Built on Xsight Labs' Programmable X2 Silicon
- Pete Verbica: America Needs Statesmanship and Common Sense — Not a Cult of Personality
- Heidi G. Villari of The Villari Firm, PLLC Recognized in The Best Lawyers in America 2027 for Construction Law and Personal Injury Litigation
- When the Coroner's Report Isn't Enough: Colorado Families Turn to Private Autopsy for Closure
- Nearly One-Third of CRE Asset Managers Make Major Capital Decisions on Gut Instinct, New Survey Finds
- RemoteBridge Names Dr. John N. Just, Ed.D. Chief Executive Officer
- Project CIVICA Report Finds 10,680 Non-Citizen Indicators on New York Voter Rolls — Including 88 Records with Recent Voting History
- New Analysis Details Three Converging Forces in AI and Workforce Policy Behind a $37 Billion GDP Reduction
- Revenue Optics Launches Pricing and Revenue Growth Management Practice, Names Shafohi Alamgir Vice President
- Popular AI planner Voiset launches version 2.0 and enters MENA at LEAP 2026 with full Arabic support
- CasaPerks and CredHub Partner to Help the Multifamily Industry Strengthen Resident Activation Through Credit-Building Rewards
- NaturismRE expands international research programme with Health & Wellbeing Survey
- L2 Aviation and Gotonomi Extend UAV Connectivity Beyond Cellular Reach
- Re:InvestorHub Launches the First AI-Powered Operating System Built for Real Estate Investors
- Nadi Plumbing Leads Charlotte in Private Fire Hydrant Services, Eyes Regional Expansion
