Trending...
- Parksy (parksy.com) Tackles the Most Common Parking Problem Nobody Talks About: Finding the Car Again
- 3ptechies Partners with Coolmuster to Give Away Data Recovery Software Licenses
- Easwe Lightweight Electric Wheelchair Collection with Travel-Focused Mobility Solutions
Research introduces a deterministic, auditable pipeline that reconstructs control flow and Metro modules, validated by round-trip re-execution across 11 compiler versions.
BROOKLYN, N.Y. - PennZone -- Symbiotic Security today announced new research and an open-source tool for deterministic decompilation of Hermes bytecode, the format used by React Native applications in production builds. The decompiler recovers readable JavaScript, including structured control flow, module boundaries, and identifiers, with deterministic output designed for security review.
Find the full research paper here https://hubs.ly/Q04pLtpM0
The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.
"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."
More on The PennZone
The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.
About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.
Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.
The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.
Resources
Find the full research paper here https://hubs.ly/Q04pLtpM0
The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.
"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."
More on The PennZone
- Redefining Proactive Care: The Rise of the Hybrid Concierge Medical Model
- As Canada and America Turn on Each Other, These Two Authors Stay On Speaking Terms
- Benny Turner Revisits Freddie King's Legacy for 50th Anniversary of His Passing
- GitKraken Names Jim Shaw CEO as Software Teams Move From AI Adoption to Multi-Agent Orchestration
- Brévant Guide Launches New National Restaurant Guide Across Canada
The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.
About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.
Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.
The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.
Resources
- Research paper download: https://hubs.ly/Q04pLtpM0
- GitHub repository: https://hubs.ly/Q04q0SwP0
Source: Symbiotic Security
0 Comments
Latest on The PennZone
- 54 Million Contract. New Chapter as AI Cybersecurity Platform Expands, Margins Surge & Management Signals Confidence. Cycurion, Inc: (NAS DAQ: CYCU)
- MommyAndMe.club Expands Parent-Child Class Directory to All 50 States and Washington, D.C
- Work 365 Deepens TD SYNNEX Integration with Automated Azure Billing
- Award-Winning Author's New Timely Book "Philly Girl" Highlights Centuries of Brave & Bold Women from Philadelphia
- RAS AP Consulting Signals Growth of Managed AP Governance With Digital Expansion, Pipeline Activation, and Trademark Filing Ahead of Esker All Access
- National Nonprofit Lights 200 Landmarks Pink and Blue for Pregnancy and Infant Loss Awareness Month
- Vegan Kingz Unveils Upgraded Digital Platform to Streamline Commercial Foodservice & Wholesale Ordering
- Steve Thompson Launches StickyHealth to Tackle the Retention Gap in the Growing GLP 1 Market
- Qscription Technologies Appoints Dr. Kimberly Beavers as Founding Clinical Advisor
- When Hope Feels Gone, Death2life Is Still Here!
- Sebastian Stroeller Publishes "The MAP Language Canon" — The Complete Practitioner's Guide to Structural Conversation
- OneVizion Appoints Zebra Technologies CIO Matt Ausman to Board of Directors
- GLADYS Magazine Celebrates their 18 Year Anniversary!
- New Townhome Building Released at Heritage at South Brunswick, Offering Private Perimeter Setting and Water Views
- Comics Veteran on Return of Teenage Mutant Ninja Turtles Characters, 3-D Projects, Collaboration with Original 'Star Wars' Toy Engineer
- Flexible Plan Investments Announces Retirement of Executive Vice President Renée Toth
- Sensory Education launches new neuro-affirming psychoeducation book, Sensory Diversity
- Break the Resume Mold: Career Valet Changes How Executives Hunt for Jobs
- Expansive New Worlds Await Peter Darrach Unveils 'The Cleopard and Other Tales from the Second Skin
- James Dooley Named King of AEO at Ceremony in Leigh, England
