Trending...
- MainConcept Easy Video API Extends Full Transcoding to Arm and NETINT VPUs
- Parents No Longer Have to Wait 3 Weeks for a Sleep Consultant: Nora Talks Tonight, Stays for 5 Days, Costs $89
- May The Worst Team Win! Loserball Kicks Off Another NFL Season of Hilarious Mayhem
Research introduces a deterministic, auditable pipeline that reconstructs control flow and Metro modules, validated by round-trip re-execution across 11 compiler versions.
BROOKLYN, N.Y. - OhioPen -- Symbiotic Security today announced new research and an open-source tool for deterministic decompilation of Hermes bytecode, the format used by React Native applications in production builds. The decompiler recovers readable JavaScript, including structured control flow, module boundaries, and identifiers, with deterministic output designed for security review.
Find the full research paper here https://hubs.ly/Q04pLtpM0
The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.
"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."
More on Ohio Pen
The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.
About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.
Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.
The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.
Resources
Find the full research paper here https://hubs.ly/Q04pLtpM0
The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.
"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."
More on Ohio Pen
- Super Rooter Expands to 190 Plumbing, Sewer, and Drain Service Locations Across the United States
- European Patent for ALS Program Expands the Story: HOPE Deploys Robotic TMS & FDA Commercialization Path Advances: NRx Pharmaceuticals: NAS DAQ: NRXP
- VICTURY Sports Announces Formation of Youth Sports League Built on the Official, Patented, and Award-Winning Keepy Uppy® Ball
- The Importance of Sharing Artistic Experiences: Joshua C. Terrell's Creative Work Around Ohio
- Highlighting the Importance of Accessible, Experience-Based Finance Writing by Joshua Terrell
The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.
About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.
Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.
The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.
Resources
- Research paper download: https://hubs.ly/Q04pLtpM0
- GitHub repository: https://hubs.ly/Q04q0SwP0
Source: Symbiotic Security
Filed Under: Artificial Intelligence
0 Comments
Latest on Ohio Pen
- Kerri Lawless Introduces New Home-Selling Option for Local Homeowners
- FDA-Cleared Zeta TMS Robotic System Moves Toward Deployment as FDA, DARPA and Commercial Catalysts Converge: NRx Pharmaceuticals (N A S D A Q: NRXP)
- Baird Medical Turns Global Expansion Into Tangible Growth: N A S D A Q: BDMD Posts 25% Revenue Surge as U.S. and International Markets Accelerate
- Shelter Structures America makes European debut at TEMPOR EXPO 2026 in Fulda, Germany
- HydroExcavation.com Relaunches With Exclusive Local Service Areas and Dedicated Hydrovac Manufacturer Directory
- Sky Quarry Enters a Powerful New Chapter: Refinery Restart Emminent, Nevada Oil Initiative and Visibility Put (NAS DAQ: SKYQ) in the Spotlight
- OneVizion Launches Vera AI, Bringing Connected Operational Context to Infrastructure Teams
- P-Wave Press Announces Pushing the Wave 2025 by L.A. Davenport
- DONGSHENG Titanium Recycling: Promoting a Closed-Loop Cycle for High-End Titanium Materials
- French Camp Academy Releases New Video Inviting Individuals to Consider a Life of Service
- LET US READ Documentary on Dyslexia and Literacy to Screen at TCL Chinese 6 in Hollywood
- Defense & Space Strategy Strengthens as New Leadership Builds on NASA Results and Expanding Multi-Orbit Opportunities for Ascent Solar Technologies
- STS Capital Partners is pleased to announce the appointment of Barry Brown as Vice President, Business Development
- Qscription Technologies and NEOPATHOLOGY CORP. Sign MOU to Bring FDA-Cleared Lung Imaging AI into U.S. Clinical Practice
- Artist and Photographer Joshua C. Terrell Launches New Website Showcasing Work Across Central Ohio
- Joshua Terrell Consulting Highlights the Importance of Business Information When Using AI
- Heritage at Manalapan Welcomes New Sales Team as Luxury Single-Family Home Community Continues to Grow
- Mandeville Pests May Pose Serious Health Risks for Your Family
- Share your workplace safety solutions at 2027 Applied Ergonomics Conference
- Parents No Longer Have to Wait 3 Weeks for a Sleep Consultant: Nora Talks Tonight, Stays for 5 Days, Costs $89
