Trending...
- FBI/DoW plot uncovered to hurt Trump/Vance through encouraged "widespread" cybersecurity breaches and racketeering theft of $80m in USDA payments
- Wings Air Helicopters Selected to Support VIP Transportation for Resorts World in New York
- Scoop Social Co. Brings Its Signature Mobile Dessert Experience to Houston This October
Research introduces a deterministic, auditable pipeline that reconstructs control flow and Metro modules, validated by round-trip re-execution across 11 compiler versions.
BROOKLYN, N.Y. - PrAtlas -- Symbiotic Security today announced new research and an open-source tool for deterministic decompilation of Hermes bytecode, the format used by React Native applications in production builds. The decompiler recovers readable JavaScript, including structured control flow, module boundaries, and identifiers, with deterministic output designed for security review.
Find the full research paper here https://hubs.ly/Q04pLtpM0
The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.
"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."
More on PrAtlas
The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.
About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.
Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.
The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.
Resources
Find the full research paper here https://hubs.ly/Q04pLtpM0
The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.
"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."
More on PrAtlas
- Ragin' Cajun Announces New Cheeseburger Seasoning on National Cheeseburger Day
- Warrant Activity, AVERSA™ Progress and a Potentially Transformative Fall Take Center Stage: Nutriband Inc. (N A S D A Q: NTRB)
- Put Your Herd on Your Phone: Kiko Nation Makes Livestock Management Simple
- Future Intelligence Think Tank Surpasses 1,000 Members Exploring Human and Artificial Intelligence
- Gary Bernstein Expands Media Leadership Role With Senior Strategic Advisor Appointment To Blacksun Private Equity
The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.
About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.
Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.
The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.
Resources
- Research paper download: https://hubs.ly/Q04pLtpM0
- GitHub repository: https://hubs.ly/Q04q0SwP0
Source: Symbiotic Security
0 Comments
Latest on PrAtlas
- Building a Diversified Healthcare Platform as Exosome Science, Telehealth, Diagnostics & Strategic Acquisitions Converge: NexTel Medical (OTCID: MAJI)
- Most Indiana Plane Crashes Happen Away from the State's Major Airports
- L2 Aviation Welcomes Jason Marshall as Vice President of Sales and Business Development
- Mom Era, Still That Girl: Family Art Tees 25% Off
- Fashion vs. Fascism - Because Democracy Should Always Be In Style
- Lee Gunn IV Shares Lessons From 40 Years in the Courtroom on PodNumbra Podcast
- Michael H. Kaplan Recognized for 17 Years on PHPA Workers' Compensation Panel and Advocacy for Professional Athletes
- International Society of Medical AI Convenes Global Faculty in Florence for ISMAI 2026
- Boston Industrial Solutions Introduces Personalized Printing Training
- Century Fasteners de Mexico Exhibiting at the 2026 Automotive & Aerospace Nearshoring Summit
- Retell AI White Label Platform for Agencies Launched by VoiceAIWrapper, With Branded Client Portals and No Per-Minute Markup
- FOCUS Names Mark Phillips Senior Vice President of Business Development
- Notaron Expands Online Notarization Access Following Wisconsin Approval
- Wings Air Helicopters Selected to Support VIP Transportation for Resorts World in New York
- Scoop Social Co. Brings Its Signature Mobile Dessert Experience to Houston This October
- The Social Capital Revolution Comes to Phoenix!
- Lawsuit Alleges American Deli Food Caused Severe Illness, Acute Kidney Failure, And Eight-day Hospitalization
- FBI/DoW plot uncovered to hurt Trump/Vance through encouraged "widespread" cybersecurity breaches and racketeering theft of $80m in USDA payments
- Bettingbladet releases H1 2026 report on the Swedish online gambling market
- Garage door installation or repair in Minnesota? Which makes more sense for your family?
