New Research: Deterministic Decompilation of Hermes Bytecode Back to Readable JavaScript

By: PRLog
ⓘ This article is third-party content and does not represent the views of this site. We make no guarantees regarding its accuracy or completeness.
Research introduces a deterministic, auditable pipeline that reconstructs control flow and Metro modules, validated by round-trip re-execution across 11 compiler versions.

BROOKLYN, N.Y. - July 20, 2026 - PRLog -- Symbiotic Security today announced new research and an open-source tool for deterministic decompilation of Hermes bytecode, the format used by React Native applications in production builds. The decompiler recovers readable JavaScript, including structured control flow, module boundaries, and identifiers, with deterministic output designed for security review.

Find the full research paper here https://hubs.ly/Q04pLtpM0

The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.

"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."

The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.

About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.

Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.

The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.

Resources

Contact
Symbiotic Security
***@symbioticsec.ai

Photos: (Click photo to enlarge)

Symbiotic Security Logo


Source: Symbiotic Security

Read Full Story - New Research: Deterministic Decompilation of Hermes Bytecode Back to Readable JavaScript | More news from this source

Press release distribution by PRLog
Report this content

If you believe this article contains misleading, harmful, or spam content, please let us know.

Report this article

More News

View More

Recent Quotes

View More
Symbol Price Change (%)
AMZN  249.99
+0.00 (0.00%)
AAPL  326.59
+0.00 (0.00%)
AMD  503.57
+0.00 (0.00%)
BAC  60.42
+0.00 (0.00%)
GOOG  351.37
+0.00 (0.00%)
META  645.85
+0.00 (0.00%)
MSFT  402.29
+0.00 (0.00%)
NVDA  203.28
+0.00 (0.00%)
ORCL  121.38
+0.00 (0.00%)
TSLA  369.57
+0.00 (0.00%)
Stock Quote API & Stock News API supplied by www.cloudquote.io
Quotes delayed at least 20 minutes.
By accessing this page, you agree to the Privacy Policy and Terms Of Service.