Popular on s4story
- Dr. Stewart Nozette Releases New Techno-Thriller The Day of Infamy – Space Pearl Harbor - 139
- For International Joke Day: Wanna Tickle that Funny Bone? Check out "Crazy Robert's Joke Book" - 117
- Sara Abbas Receives "Eniochos" Charioteer Award at 2026 Who is Who International Awards
- Sylvester Anthony III Introduces His Artist Journey with Debut Single "Cherish"
- TURRENTINE: A Family Legacy United Through Music
- The Mapping Software Behind America's Viral Maps Just Got Faster and Smarter
- The Story Tree Literacy Project Seeks Publishers and Librarians to Help Children Become Polyglots
- SUN Automation Group and KOLBUS America Align Hycorr Parts Support to Enhance Customer Service
- Mister Omaha Tries The Turf At Lone Star Park
- Disruptor Creations Pioneers New MicroAdventure Series with TravelSpike
Similar on s4story
- NextBoat's AI-Powered Marine Marketplace Gains Momentum as Record Growth Signals an Inflection Point for Investors (N Y S E American: NXB)
- Bynn Intelligence Ranks #1 in NIST Child Online Safety Evaluation for Ages 13–16
- Is the Market Missing One of the Most Undervalued Cybersecurity Companies on the Stock Market? Cycurion, Inc. (N A S D A Q: CYCU):
- Billion-Dollar Scale Global Technology Powerhouse Being Built with Expanding Government Contracts: Circle8 Group (N A S D A Q: CIRC)
- Qscription Technologies Appoints Radiology Industry Veteran Elliot Silverman to Advisory Board
- Search Is Broken. Curated Discovery Is the Future
- 2iG Solutions Launches MGA Insight, Bringing AI-Powered Business Intelligence to Managing General Agents
- Talentica Software Earns a Place Among India's Top 100 Great Mid-size Workplaces 2026
- Socialhose Launches TikTok Investigator, a Platform for Investigating TikTok Live
New Research: Deterministic Decompilation of Hermes Bytecode Back to Readable JavaScript
S For Story/10698146
Research introduces a deterministic, auditable pipeline that reconstructs control flow and Metro modules, validated by round-trip re-execution across 11 compiler versions.
BROOKLYN, N.Y. - s4story -- Symbiotic Security today announced new research and an open-source tool for deterministic decompilation of Hermes bytecode, the format used by React Native applications in production builds. The decompiler recovers readable JavaScript, including structured control flow, module boundaries, and identifiers, with deterministic output designed for security review.
Find the full research paper here https://hubs.ly/Q04pLtpM0
The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.
"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."
More on S For Story
The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.
About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.
Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.
The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.
Resources
Find the full research paper here https://hubs.ly/Q04pLtpM0
The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.
"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."
More on S For Story
- Lionheart Holdings and KEO Energy Sign Letter of Intent for Proposed Business Combination
- Marcus Christ Announces Singles: "The Hammer Goes Click" and "You Hate Me, I Hate You"
- Do Football Coaches Overthink Things?
- Fatal FOMO May be Your Last Roll of the Dice
- Book On Shelves Launches to Help Independent and Self-Published Authors Get Their Books
The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.
About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.
Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.
The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.
Resources
- Research paper download: https://hubs.ly/Q04pLtpM0
- GitHub repository: https://hubs.ly/Q04q0SwP0
Source: Symbiotic Security
0 Comments
Latest on S For Story
- Absinthia Previews The Green Fairy's Canvas at Tales of the Cocktail, Announces Upcoming Kickstarter
- Prince George's County MWA Hosts Fiction Craft Event on Conflict and Suspense with Austin Camacho
- Allstream Energy Partners Returns as a Media Partner for the 2026 API Inspection & Mechanical Integrity Summit in San Antonio
- The Moment After Death: New Novel Reveals What Happens After We Die - Backed by CIA Documents
- On Mandela Day, A Harlem Debate Asks: Is Nelson Mandela One Of History's Greatest Innovators?
- New Book - The Character of Freedom: The Scottish Enlightenment and American Slavery
- PokerStars & Ladbrokes veteran buys into Finnish news media Rahapelisanomat
- Former Judge Chris Oldner Honored as Best Lawyer by "D Magazine" for 6th Straight Year
- Missouri Hemp Businesses File Federal Lawsuit Challenging HB 2641
- SUN Automation Group and KOLBUS America Align Hycorr Parts Support to Enhance Customer Service
- Boston Industrial Solutions Launches New Citrine® SA1-370 Silicone Glue for Permanent Adhesion
- Northeast Airlines Launches New Asset Management Group
- ebookdone.com Launches: Type In a Book Idea, Get a Finished Book Ready to Publish on Amazon
- AI Visibility Labs LLC - Dallas Texas - July 16 2026
- NextBoat's AI-Powered Marine Marketplace Gains Momentum as Record Growth Signals an Inflection Point for Investors (N Y S E American: NXB)
- Author Terry Crain of the faBgear Company to Release New Book on Beatles Novelty Songs
- Earth First! Thoughtstorms, Parables, and Poems by J.T. Hollin Jr. Now Available for Pre-Order
- Stepping Off the Grid: Savista Retreat Announces New Experiential Packages in Jaipur for Travellers
- Where Is Your Faith The Movie and Sountrack
- Bynn Intelligence Ranks #1 in NIST Child Online Safety Evaluation for Ages 13–16
