AppSecNews
Mobile Security Open source Established Verified profile

Jadx

by skylot

Decompiler that converts Android DEX bytecode into readable Java source, with a command line tool and a graphical browser for APKs.

Visit github.com (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Jadx in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What it does

Jadx reads Android DEX bytecode and reconstructs Java source from it. It handles APK files, standalone DEX, AAR and JAR archives and smali input, unpacking the container, lifting the register based Dalvik instructions into an intermediate form, recovering control flow, and emitting Java that is usually close enough to the original to read at speed. Resources come along too: the binary XML manifest and resource entries are decoded so you can read the manifest as text.

The graphical interface is what most assessors actually use. It gives you a class tree, full text search across the decompiled corpus, jump to declaration and find usages navigation, and decompiled and smali views side by side for cases where the Java output is wrong. Deobfuscation support renames the short meaningless identifiers obfuscators produce into stable generated names, which makes an obfuscated application navigable even though it recovers no original semantics. The practical review workflow is: open the APK, read the manifest, search for the strings and API calls you care about, and follow the call graph.

Where it fits

This is the first tool open on a mobile tester's workstation when an Android application arrives, and it is equally useful to a developer checking what a third party SDK does inside their own build. It sits in manual review rather than in a pipeline, though the command line mode is scriptable enough to feed bulk extraction. Nothing has to be true beforehand except having the artifact and a Java runtime.

Strengths

  • Decompilation quality on typical Android code is high, and the result reads like source rather than like reconstructed bytecode.
  • The graphical browser, with search, cross references and a parallel smali view, makes navigating an unfamiliar application genuinely fast.
  • Deobfuscation naming makes renamed code workable instead of a wall of single letter identifiers, and command line mode supports scripted bulk decompilation.

Limitations

  • It decompiles only, and does not rebuild. When you need to patch and reinstall an application you pair it with a tool that handles the repackaging half.
  • Kotlin, coroutines and modern language features often decompile into awkward or partially incorrect Java, and some methods fail outright and fall back to smali.
  • Packers, control flow obfuscation and native code defeat it, and it performs no security analysis of its own: no rules, no findings, only source you have to read.

Who it suits

Every Android security reviewer, and developers investigating dependencies they did not write. It is not appropriate as an automated control, since nothing about it produces a pass or fail signal a pipeline can act on.

Used Jadx? Recommend it under your own name and title.

Recommend this tool