Popular on s4story
- Phinge Exposes Massive AI Security Risks, Claiming Its Patented Hardware-Verified Architecture Is The Only Safeguard Against Surveillance Capitalism - 130
- Ritz-Carlton Residences Houston Generates Strong Early New Construction Sales at 2120 Post Oak Blvd - 126
- New Memoir Takes Readers Along on a Post-Retirement Travel Journey - 125
- Local Independent Author Releases Southern Gothic Novel Where The Land Remembers - 107
- PricZone Launches Online Shopping Platform Offering Electronics, Gaming, and More
- James D. White Sr. Inspires Healing in New Book, What's Going On Behind the Mask?
- Ignazio Arces Wins Stevie® Award for Maverick of the Year at the 2026 International Business Awards
- Michael M. Thomas Expands Executive Leadership Across Central India Outreach and Royal Trinity School
- Intuitive Numerologist, Yvonne Sullivan, Publishes the Ultimate Guide to the NOC Divination System
- CM James Opens The Black Book 09.04 & The LiteraVerse Expansion
Similar on s4story
- Qscription Technologies Appoints Dr. Kimberly Beavers as Founding Clinical Advisor
- OneVizion Appoints Zebra Technologies CIO Matt Ausman to Board of Directors
- Break the Resume Mold: Career Valet Changes How Executives Hunt for Jobs
- Calling all healthcare process experts: Share your ideas at #HSPI2027 in Orlando
- DuoKey launches the World's First Agentic Crypto Agility Platform
- Sales Blueprint Architect Launches, Helping Sales Professionals, Business Owners, and Consultants Close More Business With AI
- 3ptechies Partners with Coolmuster to Give Away Data Recovery Software Licenses
- INAD Warriors' 4th Annual "Dancing with the INAD Stars" Gala
- Supreme Garage Door Repair Redirects Marketing Dollars Into North Texas Communities
- StockResearch AI Initiates Coverage on Apple (AAPL) With New Report Examining Valuation, AI Strategy and Future Growth
New Research: Deterministic Decompilation of Hermes Bytecode Back to Readable JavaScript
S For Story/10698146
Research introduces a deterministic, auditable pipeline that reconstructs control flow and Metro modules, validated by round-trip re-execution across 11 compiler versions.
BROOKLYN, N.Y. - s4story -- Symbiotic Security today announced new research and an open-source tool for deterministic decompilation of Hermes bytecode, the format used by React Native applications in production builds. The decompiler recovers readable JavaScript, including structured control flow, module boundaries, and identifiers, with deterministic output designed for security review.
Find the full research paper here https://hubs.ly/Q04pLtpM0
The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.
"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."
More on S For Story
The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.
About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.
Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.
The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.
Resources
Find the full research paper here https://hubs.ly/Q04pLtpM0
The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.
"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."
More on S For Story
- GLADYS Magazine Celebrates their 18 Year Anniversary!
- New Townhome Building Released at Heritage at South Brunswick, Offering Private Perimeter Setting and Water Views
- Comics Veteran on Return of Teenage Mutant Ninja Turtles Characters, 3-D Projects, Collaboration with Original 'Star Wars' Toy Engineer
- Flexible Plan Investments Announces Retirement of Executive Vice President Renée Toth
- Sensory Education launches new neuro-affirming psychoeducation book, Sensory Diversity
The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.
About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.
Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.
The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.
Resources
- Research paper download: https://hubs.ly/Q04pLtpM0
- GitHub repository: https://hubs.ly/Q04q0SwP0
Source: Symbiotic Security
0 Comments
Latest on S For Story
- Murder Leaves Clues: Lee Clark Launches A River Remembers, a Forensic Mystery
- Central Bag Company Partners with WYSIWYG Marketing and Launches a Modern Industrial Website
- DuoKey launches the World's First Agentic Crypto Agility Platform
- Counterparts Exhibition - Art is Destiny!
- Sales Blueprint Architect Launches, Helping Sales Professionals, Business Owners, and Consultants Close More Business With AI
- Logan Mascarenhas & Martin Jadoun Announce Upcoming Book
- Business & Media Executive Vikki Jones Examines Hidden Cost in New Book The Audacity of Entitlement
- Backyard Homestead Adventures Companion Workbook Celebrates First Anniversary
- Parksy (parksy.com) Tackles the Most Common Parking Problem Nobody Talks About: Finding the Car Again
- Mormon Church and Trans Spirit Medium Meet in Riveting New Historical Crime Novel
- Akiti the Hunter Launches Mission to Deliver One Million Books to One Million Children Worldwide
- GenZ life And Love Before Social Media
- 3ptechies Partners with Coolmuster to Give Away Data Recovery Software Licenses
- INAD Warriors' 4th Annual "Dancing with the INAD Stars" Gala
- The Beauty Briefing Names Gina Bordeaux Editor in Chief
- Wilber Chitambo Explores Faith, Healing, and Hope in "From Pain to Purpose: A Healing Journey"
- DAZN Review 2026: Streaming Price Worth It?
- HERAA.ai Launches First Platform to Transform Books into AI-Powered Subscription Platforms
- Dr. Pen Official Introduces Advanced Microneedling Technology for Precision Skincare at Home
- October 2026 Issue of Impact & Influence Magazine is Here. See What's Inside!
