<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator><link href="https://binary.ninja/feed.xml" rel="self" type="application/atom+xml" /><link href="https://binary.ninja/" rel="alternate" type="text/html" /><updated>2026-10-08T14:15:23+00:00</updated><id>https://binary.ninja/feed.xml</id><title type="html">Binary Ninja</title><subtitle>Binary Ninja is a modern reverse engineering platform with a scriptable and extensible decompiler.</subtitle><entry><title type="html">Reversing Engineering a Captive Portal</title><link href="https://binary.ninja/2026/10/06/reverse-engineering-airbnb-captive-portal.html" rel="alternate" type="text/html" title="Reversing Engineering a Captive Portal" /><published>2026-10-06T16:00:00+00:00</published><updated>2026-10-06T16:00:00+00:00</updated><id>https://binary.ninja/2026/10/06/reverse-engineering-airbnb-captive-portal</id><content type="html" xml:base="https://binary.ninja/2026/10/06/reverse-engineering-airbnb-captive-portal.html"><![CDATA[<p>I recently stayed at an vacation rental with a strange Wi-Fi setup. After I selected the network (SSID) and entered the WPA2 password, I was presented with a captive portal asking for a bunch of information instead of being given Internet access:</p>

<p><img src="/blog/images/stayfi-express/captive-portal-mockup.jpg" alt="A reconstructed StayFi captive portal with property-specific content replaced by placeholders" class="image max-height-600" /></p>

<p>This immediately caught my eye. Captive portals are common at hotels or on open networks, but I had not expected one at this vacation rental after entering the Wi-Fi password. So I decided to find out what was going on.</p>

<!--more-->

<h2 id="starting-with-the-network">Starting with the Network</h2>

<p>The captive portal pointed to <code class="language-plaintext highlighter-rouge">guest.stayfi.com</code>, and a quick Google search led me to the <a href="https://stayfi.com/">StayFi</a> home page which describes the product as “WiFi &amp; Guest Marketing Built For Vacation Rentals.” This looked interesting, though it was not immediately clear how it worked.</p>

<p>I asked an AI agent to map out the network topology, and it ran a few quick commands:</p>

<div class="language-sh highlighter-rouge"><div class="highlight"><pre class="highlight"><code>route <span class="nt">-n</span> get default
scutil <span class="nt">--dns</span>
arp <span class="nt">-an</span>
</code></pre></div></div>

<p>I initially assumed the captive portal was implemented by the gateway, but these commands quickly showed that the gateway and DNS server were two different hosts:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>default gateway:  192.168.x.1
DNS server:       192.168.x.y

ARP entry for gateway:  78:45:58:xx:xx:xx
ARP entry for DNS:      88:a2:9e:yy:yy:yy
</code></pre></div></div>

<p>The DNS server’s MAC prefix, <code class="language-plaintext highlighter-rouge">88:a2:9e</code>, pointed to Raspberry Pi hardware. Conveniently, the <a href="https://stayfi.com/stayfi-express/">StayFi Express</a> webpage includes a photo of the device, and it is unmistakably a Raspberry Pi. The <a href="https://hubspot.stayfi.com/knowledge/stayfi-express-use-your-existing-wifi-to-collect-guest-emails">setup guide</a> also lists configuring custom DNS as part of installation.</p>

<p>This also explains how the StayFi device can trigger the captive portal. As the DNS server, it can direct queries such as <code class="language-plaintext highlighter-rouge">captive.apple.com</code> to itself. Its local HTTP server then redirects the browser to the remote StayFi portal shown earlier. If you submit the requested information, StayFi authorizes your device for Internet access.</p>

<p>At this point, several possible bypasses came to mind. We could try a different DNS server, such as <code class="language-plaintext highlighter-rouge">1.1.1.1</code> or <code class="language-plaintext highlighter-rouge">8.8.8.8</code>, or perhaps connect through our own VPN. For the latter, we might need to know the VPN’s IP in advance. I manually changed the DNS server and the bypass worked on this network, but I still wanted to see exactly how StayFi works.</p>

<h2 id="imaging-the-device">Imaging the Device</h2>

<p>I decided to dig deeper. The operating system lives on an easily removable SD card (thanks, Raspberry Pi!), so I dumped a full disk image of it:</p>

<div class="language-sh highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="nb">sudo dd </span><span class="k">if</span><span class="o">=</span>/dev/rdisk8 <span class="se">\</span>
  <span class="nv">of</span><span class="o">=</span>stayfi-express.img <span class="se">\</span>
  <span class="nv">bs</span><span class="o">=</span>8m <span class="nv">conv</span><span class="o">=</span>noerror,sync
</code></pre></div></div>

<p>The resulting image was about 30 GB, most of which was empty space. The layout uses an A/B update scheme: two root slots allow a new system image to be installed while retaining a known-good one for rollback. A persistent data partition provides an overlay for configuration, databases, logs, and credentials.</p>

<p>After unpacking everything, the root filesystem contained mostly recognizable Linux packages. The custom part was thankfully small: three stripped AArch64 ELF binaries all built with Go 1.22.5.</p>

<table>
  <thead>
    <tr>
      <th>Component</th>
      <th style="text-align: right">Size</th>
      <th>Job</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">dnsserver</code></td>
      <td style="text-align: right">7.6 MB</td>
      <td>Resolves DNS, associates requests with client MAC addresses, applies access policy, and logs queries</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">httpserver</code></td>
      <td style="text-align: right">7.2 MB</td>
      <td>Redirects unauthenticated HTTP clients to the cloud portal and proxies selected traffic</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">stayfi-agent</code></td>
      <td style="text-align: right">7.7 MB</td>
      <td>Handles configuration, telemetry, remote commands, and device state</td>
    </tr>
  </tbody>
</table>

<p>This is one reason appliance reversing can be fun: a multi-gigabyte filesystem often reduces to a few megabytes of code that actually answers your question. The remaining data is just Linux doing Linux things.</p>

<h2 id="reverse-engineering-the-go-programs">Reverse Engineering the Go Programs</h2>

<p>Go binaries are large, but they are often generous to reverse engineers. Even in stripped executables, metadata such as <code class="language-plaintext highlighter-rouge">.gopclntab</code> can preserve package paths and function names. I asked my AI agent to recover those names and analyze the binaries with the help of <a href="https://docs.binary.ninja/guide/mcp.html">Binary Ninja’s MCP server</a>. The overall design became clear quickly.</p>

<p>The HTTP service uses Go’s standard <code class="language-plaintext highlighter-rouge">net/http</code> stack and <code class="language-plaintext highlighter-rouge">net/http/httputil.ReverseProxy</code>. The DNS service uses the well-known <a href="https://github.com/miekg/dns"><code class="language-plaintext highlighter-rouge">miekg/dns</code></a> package. Both use SQLite for local state. Using existing protocol libraries meant I could focus my analysis on the policy wrapped around them.</p>

<p>In simplified Go-like pseudocode, the HTTP flow looked roughly like this:</p>

<div class="language-go highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="n">clientMAC</span> <span class="o">:=</span> <span class="n">macForIP</span><span class="p">(</span><span class="n">request</span><span class="o">.</span><span class="n">RemoteAddr</span><span class="p">)</span>

<span class="k">if</span> <span class="n">isAuthorized</span><span class="p">(</span><span class="n">clientMAC</span><span class="p">)</span> <span class="p">{</span>
    <span class="n">proxyRequest</span><span class="p">(</span><span class="n">request</span><span class="p">)</span>
    <span class="k">return</span>
<span class="p">}</span>

<span class="k">if</span> <span class="n">matchesSmartConnect</span><span class="p">(</span><span class="n">request</span><span class="o">.</span><span class="n">UserAgent</span><span class="p">)</span> <span class="p">{</span>
    <span class="k">go</span> <span class="n">authorizeWithCloud</span><span class="p">(</span><span class="n">clientMAC</span><span class="p">)</span>
    <span class="n">proxyRequest</span><span class="p">(</span><span class="n">request</span><span class="p">)</span>
    <span class="k">return</span>
<span class="p">}</span>

<span class="n">redirectToCaptivePortal</span><span class="p">(</span><span class="n">clientMAC</span><span class="p">)</span>
</code></pre></div></div>

<p>For each client request, the appliance maps the source IP address back to a MAC address using its ARP table, with <code class="language-plaintext highlighter-rouge">arping</code> as a fallback. The MAC address becomes the local identity. SQLite records whether that identity is authorized, blocked, or eligible for a bypass rule.</p>

<p>DNS and HTTP then cooperate as DNS applies the client’s policy and records the query. When an unauthenticated browser makes a plain HTTP request, the HTTP service sends a redirect resembling:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>https://guest.stayfi.com/sbc/captive_portal?sbc_mac=&lt;appliance&gt;&amp;client_mac=&lt;guest&gt;
</code></pre></div></div>

<p>Notice that this is no longer on the local device—the request goes to a remote server.</p>

<p>According to StayFi’s <a href="https://stayfi.com/privacy-policy/">privacy policy</a> (last updated July 31, 2025), StayFi may disclose personal information such as email addresses, device identifiers, phone numbers, and usage information to the property manager. It may also share information with advertising partners.</p>

<p>I even tried entering a syntactically valid but fake-looking email address. The webpage had no issue with it, but the server rejected it. StayFi’s <a href="https://hubspot.stayfi.com/knowledge/setting-up-your-stayfi-account">setup documentation</a> says its optional valid-email check uses ZeroBounce, which is consistent with the rejection I observed. That check validates an email address; it does not establish the identity of the person entering it.</p>

<h2 id="a-serious-privacy-concern">A Serious Privacy Concern</h2>

<p>A closer look at the DNS server showed that it logs requests to <code class="language-plaintext highlighter-rouge">dnsserver.log</code>. A <a href="https://www.datadoghq.com/">Datadog</a> agent tails this file, with a configuration to forward the DNS logs to that third-party service.</p>

<p>The log recovered from my device covered about three and a half hours. It contained 11,801 DNS-request records representing 639 unique domain names. Packet captures showed sustained connections to Datadog log-intake infrastructure, consistent with that configuration.</p>

<p>DNS logs show which domain names a device looked up and when. They can suggest which services it used, but background applications and prefetching also generate queries, so a lookup does not prove that a person visited a website. Because the registration form sends the guest’s name, email, phone number, client MAC address, appliance MAC address, and property identifiers, these records could be linked to an identified guest, although I found no evidence showing whether or how often StayFi performs that correlation.</p>

<p>The privacy policy also says that StayFi automatically collects “Usage Information” and a “Device Identifier,” including IP and MAC addresses. More directly, it says StayFi “collects your network traffic information.”</p>

<p>The policy says it will not use this information “for any purpose other than to administer the Services”—for example, to maintain and secure the network, answer service-related questions, or respond to legal requirements. Elsewhere, it describes sharing personal or usage information with the property manager, service providers working on StayFi’s behalf, and, in some circumstances, advertising partners.</p>

<p>If you find this a little confusing, I felt the same way. It’s difficult to tell how they actually handle the data.</p>

<h2 id="little-surprises">Little Surprises</h2>

<p>Finding unexpected details is one of the best parts of reverse engineering, and this device did not let me down. For example, it whitelists certain device names and MAC address ranges associated with smart TVs and other IoT devices. This makes sense because you obviously cannot type your phone number into a smart speaker.</p>

<p>The downloaded regular expressions matched terms including:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>tv, smart-tv, hbbtv, Roku, Fire TV, Apple TV, Chromecast,
Tizen, webOS, Sonos, thermostat, door lock, Home Assistant,
Nest, PlayStation, Xbox
</code></pre></div></div>

<p>The MAC whitelist contained 285 organizationally unique identifiers (OUIs). These are three-byte vendor prefixes rather than complete device addresses. A few examples were:</p>

<table>
  <thead>
    <tr>
      <th>Vendor</th>
      <th>Whitelisted prefixes</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>Vizio</td>
      <td><code class="language-plaintext highlighter-rouge">00:bd:3e</code>, <code class="language-plaintext highlighter-rouge">0c:8b:7d</code>, <code class="language-plaintext highlighter-rouge">3c:9b:d6</code>, <code class="language-plaintext highlighter-rouge">a0:6a:44</code></td>
    </tr>
    <tr>
      <td>Texas Instruments</td>
      <td><code class="language-plaintext highlighter-rouge">0c:1c:57</code>, <code class="language-plaintext highlighter-rouge">10:08:2c</code>, <code class="language-plaintext highlighter-rouge">6c:79:b8</code></td>
    </tr>
    <tr>
      <td>Ubiquiti</td>
      <td><code class="language-plaintext highlighter-rouge">d0:21:f9</code></td>
    </tr>
  </tbody>
</table>

<p>The device also comes with a WireGuard profile. A heavily redacted and abridged version looks like this:</p>

<div class="language-ini highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="c"># /etc/wireguard/wg-client.conf
</span><span class="nn">[Interface]</span><span class="w">
</span><span class="py">PrivateKey</span><span class="w"> </span><span class="p">=</span><span class="w"> </span><span class="s">&lt;redacted&gt;</span>
<span class="py">Address</span><span class="w"> </span><span class="p">=</span><span class="w"> </span><span class="s">10.39.x.y/32</span>
<span class="w">
</span><span class="nn">[Peer]</span><span class="w">
</span><span class="py">PublicKey</span><span class="w"> </span><span class="p">=</span><span class="w"> </span><span class="s">&lt;redacted&gt;</span>
<span class="py">Endpoint</span><span class="w"> </span><span class="p">=</span><span class="w"> </span><span class="s">&lt;redacted&gt;:51820</span>
<span class="py">AllowedIPs</span><span class="w"> </span><span class="p">=</span><span class="w"> </span><span class="s">10.39.x.1/32, ..., 10.39.x.10/32</span>
</code></pre></div></div>

<p>The narrow <code class="language-plaintext highlighter-rouge">AllowedIPs</code> means WireGuard routes traffic only to a small set of management hosts, not all of the appliance’s Internet traffic.</p>

<p>The root account also has six authorized SSH keys that appear to be associated with StayFi:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code># /root/.ssh/authorized_keys
ssh-ed25519 &lt;key-redacted&gt; it@stayfi.com
ssh-ed25519 &lt;key-redacted&gt; it@stayfi.com
ssh-ed25519 &lt;key-redacted&gt; &lt;name&gt;@stayfi.com
ssh-ed25519 &lt;key-redacted&gt; &lt;name&gt;@stayfi.com
ssh-ed25519 &lt;key-redacted&gt; &lt;name&gt;@stayfi.com
ssh-ed25519 &lt;key-redacted&gt; &lt;local-hostname&gt;
</code></pre></div></div>

<p>This presumably allows StayFi operators to access the box remotely for tasks such as troubleshooting.</p>

<p>The next time a captive portal Wi-Fi asks for your phone number, maybe change your hostname to “tv” and see if you still get blocked!</p>

<p><em>Editor’s Note (Jordan here): Fun fact, we did in fact get a bunch of text spam after the offsite and have even had the system re-subscribe our number after we requested the office number be removed</em></p>]]></content><author><name>Xusheng Li</name><email>xusheng@vector35.com</email></author><category term="reversing" /><category term="security" /><summary type="html"><![CDATA[Inside a StayFi Express captive portal: reverse engineering its Go services, DNS policy, guest registration, and logging with Binary Ninja.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://binary.ninja/blog/images/stayfi-express/captive-portal-mockup.jpg" /><media:content medium="image" url="https://binary.ninja/blog/images/stayfi-express/captive-portal-mockup.jpg" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">Debugger Conditional Breakpoints and the Expression Parser That Backs Them</title><link href="https://binary.ninja/2026/09/29/debugger-conditional-breakpoint.html" rel="alternate" type="text/html" title="Debugger Conditional Breakpoints and the Expression Parser That Backs Them" /><published>2026-09-29T13:00:00+00:00</published><updated>2026-09-29T13:00:00+00:00</updated><id>https://binary.ninja/2026/09/29/debugger-conditional-breakpoint</id><content type="html" xml:base="https://binary.ninja/2026/09/29/debugger-conditional-breakpoint.html"><![CDATA[<p>In Binary Ninja’s debugger, when you set a breakpoint and add a condition like <code class="language-plaintext highlighter-rouge">rax == 0x1234</code>, it just works. Let’s take a look into how that works and what sorts of conditions you can use.</p>

<p>This post tells the story of the <a href="https://docs.binary.ninja/guide/debugger/index.html#conditional-breakpoints">conditional breakpoint</a> with a side-quest to explore Binary Ninja’s <a href="https://api.binary.ninja/binaryninja.binaryview-module.html#binaryninja.binaryview.BinaryView.parse_expression">expression parser</a> which is the feature that makes it possible.</p>

<!--more-->

<h2 id="it-started-with-navigation">It Started with Navigation</h2>

<p>If you’ve used Binary Ninja, you’ve probably pressed <code class="language-plaintext highlighter-rouge">G</code> to open the navigation dialog and typed in a function name. But did you know that dialog is powered by a full expression parser? This means you can type <code class="language-plaintext highlighter-rouge">main + 0x10</code> to navigate 16 bytes past the start of <code class="language-plaintext highlighter-rouge">main</code>, or <code class="language-plaintext highlighter-rouge">.text + 0x100</code> to jump to an offset within a section, or even <code class="language-plaintext highlighter-rouge">[.data + 0x20]</code> to dereference a pointer.</p>

<p>The expression parser can do a lot more than you would probably guess. Here’s some examples:</p>

<h3 id="expression-parser-capabilities">Expression Parser Capabilities</h3>

<table>
  <thead>
    <tr>
      <th>Feature</th>
      <th>Example</th>
      <th>Description</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>Arithmetic</td>
      <td><code class="language-plaintext highlighter-rouge">main + 0x10</code></td>
      <td>Navigate 16 bytes after main</td>
    </tr>
    <tr>
      <td>Sections</td>
      <td><code class="language-plaintext highlighter-rouge">.text + 0x100</code></td>
      <td>Offset into a section</td>
    </tr>
    <tr>
      <td>Symbols</td>
      <td><code class="language-plaintext highlighter-rouge">data_00005000</code></td>
      <td>Unnamed data variables</td>
    </tr>
    <tr>
      <td>Dereference</td>
      <td><code class="language-plaintext highlighter-rouge">[.data + 0x20]</code></td>
      <td>Read pointer at address</td>
    </tr>
    <tr>
      <td>Size suffix</td>
      <td><code class="language-plaintext highlighter-rouge">[.data + 0x20].q</code></td>
      <td>Read 8 bytes (quadword)</td>
    </tr>
    <tr>
      <td>Special values</td>
      <td><code class="language-plaintext highlighter-rouge">$here</code>, <code class="language-plaintext highlighter-rouge">$start</code>, <code class="language-plaintext highlighter-rouge">$end</code></td>
      <td>Current address, file boundaries</td>
    </tr>
  </tbody>
</table>

<p>The supported operators include arithmetic (<code class="language-plaintext highlighter-rouge">+</code>, <code class="language-plaintext highlighter-rouge">-</code>, <code class="language-plaintext highlighter-rouge">*</code>, <code class="language-plaintext highlighter-rouge">/</code>, <code class="language-plaintext highlighter-rouge">%</code>), bitwise operations (<code class="language-plaintext highlighter-rouge">&amp;</code>, <code class="language-plaintext highlighter-rouge">|</code>, <code class="language-plaintext highlighter-rouge">^</code>, <code class="language-plaintext highlighter-rouge">~</code>), comparisons (<code class="language-plaintext highlighter-rouge">==</code>, <code class="language-plaintext highlighter-rouge">!=</code>, <code class="language-plaintext highlighter-rouge">&gt;</code>, <code class="language-plaintext highlighter-rouge">&lt;</code>, <code class="language-plaintext highlighter-rouge">&gt;=</code>, <code class="language-plaintext highlighter-rouge">&lt;=</code>), and grouping with parentheses.</p>

<p>For memory dereferences, you can specify the size: <code class="language-plaintext highlighter-rouge">[expr].b</code> for a byte, <code class="language-plaintext highlighter-rouge">[expr].w</code> for a word, <code class="language-plaintext highlighter-rouge">[expr].d</code> for a dword, and <code class="language-plaintext highlighter-rouge">[expr].q</code> for a quadword. Without a suffix, it reads an address-sized value.</p>

<p>Numbers default to hexadecimal, but you can use <code class="language-plaintext highlighter-rouge">0n10</code> for decimal or <code class="language-plaintext highlighter-rouge">010</code> for octal when needed.</p>

<p>For the complete specification, see the <a href="https://api.binary.ninja/binaryninja.binaryview-module.html#binaryninja.binaryview.BinaryView.parse_expression">parse_expression API documentation</a>.</p>

<h2 id="making-it-dynamic-magic-values">Making It Dynamic: Magic Values</h2>

<p>The expression parser becomes even more powerful during debugging thanks to “magic values” which are name-value pairs that can be registered at runtime.</p>

<p>When you’re in a debug session, the debugger automatically registers all CPU registers (<code class="language-plaintext highlighter-rouge">rax</code>, <code class="language-plaintext highlighter-rouge">rbx</code>, <code class="language-plaintext highlighter-rouge">rsp</code>, <code class="language-plaintext highlighter-rouge">rbp</code>, <code class="language-plaintext highlighter-rouge">rip</code>, etc.) and module bases (<code class="language-plaintext highlighter-rouge">kernel32</code>, <code class="language-plaintext highlighter-rouge">ntdll</code>, <code class="language-plaintext highlighter-rouge">libc</code>, etc.) into the expression parser. This enables some useful workflows:</p>

<ul>
  <li>Type <code class="language-plaintext highlighter-rouge">rbp - 0x20</code> to navigate directly to a stack variable — no manual calculation needed</li>
  <li>Type <code class="language-plaintext highlighter-rouge">kernel32 + 0x1000</code> to navigate into a loaded module, even with ASLR</li>
  <li>Type <code class="language-plaintext highlighter-rouge">rsp</code> to jump straight to the stack pointer</li>
</ul>

<p><img src="/blog/images/conditional-breakpoint/1.png" alt="Navigate dialog with register expression" class="image max-height-500" /></p>

<p><em>A quick note: historically, register names required a <code class="language-plaintext highlighter-rouge">$</code> prefix (e.g., <code class="language-plaintext highlighter-rouge">$rax</code>). Register names can now be used directly, as in <code class="language-plaintext highlighter-rouge">rax</code>.</em></p>

<p>Plugin authors can take advantage of this system too. The <a href="https://api.binary.ninja/binaryninja.binaryview-module.html#binaryninja.binaryview.BinaryView.add_expression_parser_magic_value">add_expression_parser_magic_value</a> API lets you register custom values. Imagine registering heap chunk addresses or TLS slots that users can then reference directly in expressions.</p>

<h2 id="the-500-line-feature">The 500-Line Feature</h2>

<p>Conditional breakpoint support landed in December 2025, thanks to a PR from community contributor <a href="https://github.com/3rdit">3rdit</a>. The entire feature (condition evaluation, UI, and API) took about 500 lines of code.</p>

<p>How is it possible to implement such a major feature in just 500 lines? The secret is that the condition evaluation uses the expression parser we just discussed. Here’s a simplified version of <a href="https://github.com/Vector35/debugger/blob/2e0c5f6d031bf4a2e30c0333715fbafbfd714115/core/debuggercontroller.cpp#L2559-L2577">how it works</a>:</p>

<div class="language-cpp highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="kt">bool</span> <span class="n">DebuggerController</span><span class="o">::</span><span class="n">EvaluateBreakpointCondition</span><span class="p">(</span><span class="kt">uint64_t</span> <span class="n">address</span><span class="p">)</span>
<span class="p">{</span>
    <span class="k">const</span> <span class="n">std</span><span class="o">::</span><span class="n">string</span> <span class="n">condition</span> <span class="o">=</span> <span class="n">m_state</span><span class="o">-&gt;</span><span class="n">GetBreakpoints</span><span class="p">()</span><span class="o">-&gt;</span><span class="n">GetConditionAbsolute</span><span class="p">(</span><span class="n">address</span><span class="p">);</span>
    <span class="k">if</span> <span class="p">(</span><span class="n">condition</span><span class="p">.</span><span class="n">empty</span><span class="p">())</span>
        <span class="k">return</span> <span class="nb">true</span><span class="p">;</span>  <span class="c1">// No condition means always stop</span>

    <span class="c1">// Use the expression parser to evaluate the condition</span>
    <span class="kt">uint64_t</span> <span class="n">result</span> <span class="o">=</span> <span class="mi">0</span><span class="p">;</span>
    <span class="n">std</span><span class="o">::</span><span class="n">string</span> <span class="n">error</span><span class="p">;</span>
    <span class="k">if</span> <span class="p">(</span><span class="o">!</span><span class="n">BinaryView</span><span class="o">::</span><span class="n">ParseExpression</span><span class="p">(</span><span class="n">GetData</span><span class="p">(),</span> <span class="n">condition</span><span class="p">,</span> <span class="n">result</span><span class="p">,</span> <span class="n">address</span><span class="p">,</span> <span class="n">error</span><span class="p">))</span>
        <span class="k">return</span> <span class="nb">true</span><span class="p">;</span>  <span class="c1">// Parse error, stop to be safe</span>

    <span class="k">return</span> <span class="n">result</span> <span class="o">!=</span> <span class="mi">0</span><span class="p">;</span>  <span class="c1">// Non-zero means condition is true</span>
<span class="p">}</span>
</code></pre></div></div>

<p>The debugger simply calls <code class="language-plaintext highlighter-rouge">ParseExpression</code> on the condition string. If the result is non-zero, the condition is true and the debugger stops. That’s it. All the heavy lifting including parsing the expression, reading register values, performing arithmetic and comparisons is handled by the expression parser.</p>

<p>Because the condition is evaluated at the debugger core level rather than the adapter level, the same expression syntax is available across supported debugger adapters. The register and module names in an expression still depend on the target.</p>

<h2 id="but-wait--comparison-operators">But Wait — Comparison Operators?</h2>

<p>You might be wondering: how does the expression parser handle conditions like <code class="language-plaintext highlighter-rouge">rax == 0x1234</code>? After all, it was originally a navigation feature. What does a comparison even mean in that context?</p>

<p>Back in December 2022, while I was adding the magic value support for register values, I also added comparison operators to the expression parser: <code class="language-plaintext highlighter-rouge">==</code>, <code class="language-plaintext highlighter-rouge">!=</code>, <code class="language-plaintext highlighter-rouge">&gt;</code>, <code class="language-plaintext highlighter-rouge">&lt;</code>, <code class="language-plaintext highlighter-rouge">&gt;=</code>, <code class="language-plaintext highlighter-rouge">&lt;=</code>. These operators return <code class="language-plaintext highlighter-rouge">1</code> if the condition is true, <code class="language-plaintext highlighter-rouge">0</code> otherwise.</p>

<p>I was already thinking ahead for conditional breakpoints. The expression parser already knew how to read register values and dereference memory locations making it a perfect match for evaluating breakpoint conditions. Adding comparison operators made it ready to use.</p>

<p>Then in December 2025, <a href="https://github.com/3rdit">3rdit</a> reached out asking about adding conditional breakpoint support. I was excited — the foundation I’d laid three years earlier was finally going to be used. I told him that the expression parser was already there to support it so it shouldn’t be hard. He came back with <a href="https://github.com/Vector35/debugger/pull/941">PR #941</a>, which was merged with little modification.</p>

<p>Thanks to 3rdit for the contribution!</p>

<h2 id="how-to-use-conditional-breakpoints">How to Use Conditional Breakpoints</h2>

<p>Here’s how to add a condition to a breakpoint.</p>

<h3 id="setting-a-condition">Setting a Condition</h3>

<ol>
  <li>Add a breakpoint at the desired location</li>
  <li>Right-click the breakpoint in the Breakpoints widget</li>
  <li>Select “Edit Condition…”</li>
  <li>Enter your condition expression</li>
  <li>Click OK</li>
</ol>

<p><img src="/blog/images/conditional-breakpoint/2.png" alt="Edit condition dialog" class="image max-height-500" /></p>

<p>You can also view and edit conditions in the “Condition” column of the Breakpoints widget.</p>

<p><img src="/blog/images/conditional-breakpoint/3.png" alt="Breakpoint condition in the breakpoint widget" class="image max-height-500" /></p>

<h3 id="example-conditions">Example Conditions</h3>

<p>These examples use x86-64 register names. Use the register names for your target architecture.</p>

<table>
  <thead>
    <tr>
      <th>Condition</th>
      <th>When to stop</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">rax == 0x1234</code></td>
      <td><code class="language-plaintext highlighter-rouge">rax</code> equals a specific value</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">rax != 0</code></td>
      <td><code class="language-plaintext highlighter-rouge">rax</code> is non-zero</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">rcx &lt; 0n10</code></td>
      <td><code class="language-plaintext highlighter-rouge">rcx</code> is less than decimal 10</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">[rsp] == 0</code></td>
      <td>The address-sized value at the stack pointer is zero</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">rdi == rbp - 0x20</code></td>
      <td><code class="language-plaintext highlighter-rouge">rdi</code> equals a stack address</td>
    </tr>
  </tbody>
</table>

<p>Remember that unprefixed numbers are hexadecimal: <code class="language-plaintext highlighter-rouge">10</code> means sixteen; <code class="language-plaintext highlighter-rouge">0n10</code> means ten.</p>

<h3 id="using-the-api">Using the API</h3>

<p>In Binary Ninja’s Python console, <code class="language-plaintext highlighter-rouge">dbg</code> is the debugger controller for the current view. These examples assume you have already added breakpoints at the specified locations. Replace the addresses and module name with values from your target.</p>

<div class="language-python highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="kn">from</span> <span class="n">binaryninja.debugger</span> <span class="kn">import</span> <span class="n">ModuleNameAndOffset</span>

<span class="c1"># Set a condition
</span><span class="n">dbg</span><span class="p">.</span><span class="nf">set_breakpoint_condition</span><span class="p">(</span><span class="mh">0x401000</span><span class="p">,</span> <span class="sh">"</span><span class="s">rax == 0x1234</span><span class="sh">"</span><span class="p">)</span>

<span class="c1"># With module-relative address
</span><span class="n">dbg</span><span class="p">.</span><span class="nf">set_breakpoint_condition</span><span class="p">(</span><span class="nc">ModuleNameAndOffset</span><span class="p">(</span><span class="sh">"</span><span class="s">myprogram</span><span class="sh">"</span><span class="p">,</span> <span class="mh">0x1000</span><span class="p">),</span> <span class="sh">"</span><span class="s">rdi != 0</span><span class="sh">"</span><span class="p">)</span>

<span class="c1"># Get current condition
</span><span class="n">condition</span> <span class="o">=</span> <span class="n">dbg</span><span class="p">.</span><span class="nf">get_breakpoint_condition</span><span class="p">(</span><span class="mh">0x401000</span><span class="p">)</span>

<span class="c1"># Clear condition (set to empty string)
</span><span class="n">dbg</span><span class="p">.</span><span class="nf">set_breakpoint_condition</span><span class="p">(</span><span class="mh">0x401000</span><span class="p">,</span> <span class="sh">""</span><span class="p">)</span>
</code></pre></div></div>

<p>For more details, see the <a href="https://docs.binary.ninja/guide/debugger/index.html#conditional-breakpoints">conditional breakpoints documentation</a>.</p>

<h2 id="whats-next">What’s Next</h2>

<p>The expression parser continues to evolve. One possible extension would be a string comparison function such as <code class="language-plaintext highlighter-rouge">streq</code>. For example, a hypothetical <code class="language-plaintext highlighter-rouge">streq(rdi, "password")</code> could stop when <code class="language-plaintext highlighter-rouge">rdi</code> points to that string. This is an idea for future work, not syntax you can use today.</p>

<p>We’d love to hear your feedback on what would make conditional breakpoints even more useful for your workflows.</p>

<p>Next time you press <code class="language-plaintext highlighter-rouge">G</code> in Binary Ninja, remember that you have a full expression parser at your fingertips. Skip the calculator and just use <code class="language-plaintext highlighter-rouge">rbp - 0x20</code> during your next debugging session.</p>

<h2 id="references">References</h2>

<h3 id="documentation">Documentation</h3>
<ul>
  <li><a href="https://api.binary.ninja/binaryninja.binaryview-module.html#binaryninja.binaryview.BinaryView.parse_expression">Expression Parser API (parse_expression)</a></li>
  <li><a href="https://api.binary.ninja/binaryninja.binaryview-module.html#binaryninja.binaryview.BinaryView.add_expression_parser_magic_value">Magic Values API (add_expression_parser_magic_value)</a></li>
  <li><a href="https://docs.binary.ninja/guide/debugger/index.html#conditional-breakpoints">Conditional Breakpoints Guide</a></li>
</ul>

<h3 id="implementation">Implementation</h3>
<ul>
  <li><a href="https://github.com/Vector35/debugger/pull/941">Conditional Breakpoints PR #941</a></li>
  <li><a href="https://github.com/Vector35/debugger/commit/2296ddb629d252c2838055a844008f383dd31910">Step-vs-Breakpoint Fix</a></li>
  <li><a href="https://github.com/Vector35/debugger/issues/93">Feature Request Issue #93</a></li>
</ul>]]></content><author><name>Xusheng Li</name><email>xusheng@vector35.com</email></author><category term="debugger" /><summary type="html"><![CDATA[How Binary Ninja’s navigation expression parser powers conditional breakpoints, with examples for registers, memory, and the debugger API.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://binary.ninja/blog/images/conditional-breakpoint/2.png" /><media:content medium="image" url="https://binary.ninja/blog/images/conditional-breakpoint/2.png" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">Binary Ninja 6.0 (Krypton)</title><link href="https://binary.ninja/2026/09/03/binary-ninja-6.0-krypton.html" rel="alternate" type="text/html" title="Binary Ninja 6.0 (Krypton)" /><published>2026-09-03T19:37:00+00:00</published><updated>2026-09-03T19:37:00+00:00</updated><id>https://binary.ninja/2026/09/03/binary-ninja-6.0-krypton</id><content type="html" xml:base="https://binary.ninja/2026/09/03/binary-ninja-6.0-krypton.html"><![CDATA[<p><img src="/blog/images/6.0-release/krypton.jpg" alt="Caped Binja flying over the city. &gt;" class="image max-height-300" /></p>

<p>Binary Ninja 6.0 (Krypton) is here! This is a major version bump, and it’s worth the wait. We’ve shipped a brand new <a href="/2026/09/03/binary-ninja-6.0-krypton.html#mcp">MCP server</a>, a new <a href="/2026/09/03/binary-ninja-6.0-krypton.html#binary-similarity">Binary Similarity</a> feature, and a complete overhaul of the Plugin Manager as the new <a href="/2026/09/03/binary-ninja-6.0-krypton.html#extension-manager">Extension Manager</a>. Under the hood, you’ll find major improvements to <a href="/2026/09/03/binary-ninja-6.0-krypton.html#performance-and-memory">performance and memory usage</a>, a refactored <a href="/2026/09/03/binary-ninja-6.0-krypton.html#calling-convention-refactor">calling convention</a> to properly represent structure parameters and return values, and added <a href="/2026/09/03/binary-ninja-6.0-krypton.html#hlil_struct_initialize">HLIL structure initializers</a>. On the scripting side, we’ve updated the bundled Python version to <a href="/2026/09/03/binary-ninja-6.0-krypton.html#python-313-and-linux">3.13</a> and included it on Linux. We’ve also added a new <a href="/2026/09/03/binary-ninja-6.0-krypton.html#tms320c6x">TMS320C6x</a> architecture, a <a href="/2026/09/03/binary-ninja-6.0-krypton.html#new-user-wizard">new user wizard</a> to ease migration, and a long list of <a href="/2026/09/03/binary-ninja-6.0-krypton.html#debugger">debugger improvements</a>. And those are still only some of the new features detailed below.</p>

<p>We’re also improving the <a href="/2026/09/03/binary-ninja-6.0-krypton.html#new-features-in-free">free edition</a>. We’ve added the highly requested <code class="language-plaintext highlighter-rouge">armv8</code> (AArch64) architecture as well as the above-mentioned MCP server. Additionally, we’re also shipping a new Linux ARM64 build of the free version. Next, as <a href="/2026/07/28/pricing-changes.html">previously announced</a>, with this release we’re putting our new <a href="/2026/09/03/binary-ninja-6.0-krypton.html#pricing-and-packaging">pricing and packaging</a> into effect. Finally, thanks to everyone who participated in our <a href="/2026/07/22/10-years-of-binary-ninja.html">10 year celebration</a>! We’re looking forward to another decade!</p>

<!--more-->

<ul>
  <li><a href="/2026/09/03/binary-ninja-6.0-krypton.html#performance-and-memory">Performance and Memory</a>
    <ul>
      <li><a href="/2026/09/03/binary-ninja-6.0-krypton.html#analysis-cache">Analysis Cache</a></li>
      <li><a href="/2026/09/03/binary-ninja-6.0-krypton.html#database-saving">Database Saving</a></li>
    </ul>
  </li>
  <li><a href="/2026/09/03/binary-ninja-6.0-krypton.html#mcp">MCP</a></li>
  <li><a href="/2026/09/03/binary-ninja-6.0-krypton.html#binary-similarity">Binary Similarity</a></li>
  <li><a href="/2026/09/03/binary-ninja-6.0-krypton.html#architectures-and-platforms">Architectures and Platforms</a>
    <ul>
      <li><a href="/2026/09/03/binary-ninja-6.0-krypton.html#tms320c6x">TMS320C6x</a></li>
      <li><a href="/2026/09/03/binary-ninja-6.0-krypton.html#multiple-global-pointers">Multiple Global Pointers</a></li>
    </ul>
  </li>
  <li><a href="/2026/09/03/binary-ninja-6.0-krypton.html#analysis">Analysis</a>
    <ul>
      <li><a href="/2026/09/03/binary-ninja-6.0-krypton.html#improved-base-fast-analysis-mode">Improved BASE (Fast Analysis Mode)</a></li>
      <li><a href="/2026/09/03/binary-ninja-6.0-krypton.html#calling-convention-refactor">Calling Convention Refactor</a></li>
      <li><a href="/2026/09/03/binary-ninja-6.0-krypton.html#hlil_struct_initialize">HLIL_STRUCT_INITIALIZE</a></li>
      <li><a href="/2026/09/03/binary-ninja-6.0-krypton.html#type-fragments">Type Fragments</a></li>
    </ul>
  </li>
  <li><a href="/2026/09/03/binary-ninja-6.0-krypton.html#scripting-and-extensions">Scripting and Extensions</a>
    <ul>
      <li><a href="/2026/09/03/binary-ninja-6.0-krypton.html#python-313-and-linux">Python 3.13 and Linux</a></li>
      <li><a href="/2026/09/03/binary-ninja-6.0-krypton.html#scripting-console">Scripting Console</a></li>
      <li><a href="/2026/09/03/binary-ninja-6.0-krypton.html#extension-manager">Extension Manager</a></li>
    </ul>
  </li>
  <li><a href="/2026/09/03/binary-ninja-6.0-krypton.html#new-user-wizard">New User Wizard</a></li>
  <li><a href="/2026/09/03/binary-ninja-6.0-krypton.html#debugger">Debugger</a></li>
  <li><a href="/2026/09/03/binary-ninja-6.0-krypton.html#packaging-and-licensing">Packaging and Licensing</a>
    <ul>
      <li><a href="/2026/09/03/binary-ninja-6.0-krypton.html#new-features-in-free">New Features in Free</a></li>
      <li><a href="/2026/09/03/binary-ninja-6.0-krypton.html#pricing-and-packaging">Pricing and Packaging</a></li>
      <li><a href="/2026/09/03/binary-ninja-6.0-krypton.html#server-deployments">Server Deployments</a></li>
    </ul>
  </li>
  <li><a href="/2026/09/03/binary-ninja-6.0-krypton.html#open-source-contributions">Open-Source Contributions</a></li>
  <li><a href="/2026/09/03/binary-ninja-6.0-krypton.html#everything-else">Everything Else</a></li>
</ul>

<h1 id="major-features">Major Features</h1>

<h2 id="performance-and-memory">Performance and Memory</h2>

<p>Let’s start with some some universally applicable improvements. No matter how you use Binary Ninja, you’ll see some fantastic speedups in 6.0 while also seeing decreases in memory usage. Exact improvements depend on the workload and hardware, so we picked some representative sample binaries and ran a gamut of testing. The results speak for themselves.</p>

<div class="perf-compare">
  <p class="perf-key">
    <span><i class="perf-swatch-before"></i>5.3 stable</span>
    <span><i class="perf-swatch-after"></i>6.0 stable</span>
  </p>

  <div class="perf-rows">
    <div class="perf-row">
      <div class="perf-id">
        <p class="perf-name">syspolicyd</p>
        <p class="perf-format">Mach-O universal, x86-64 slice</p>
        <p class="perf-scale"><span>4,215 functions</span><span>2.6 MB</span></p>
      </div>
      <div class="perf-metrics">
        <div>
          <span class="perf-label">Analysis time</span>
          <div class="perf-pair">
            <div class="perf-track"><div class="perf-bar before" style="width:100%"></div></div>
            <span class="perf-value old">13.8s</span>
            <div class="perf-track"><div class="perf-bar after" style="width:50.8%"></div></div>
            <span class="perf-value new">7.0s</span>
          </div>
          <p class="perf-delta">1.97&times; faster</p>
        </div>
        <div>
          <span class="perf-label">Peak memory</span>
          <div class="perf-pair">
            <div class="perf-track"><div class="perf-bar before" style="width:100%"></div></div>
            <span class="perf-value old">2.81 GB</span>
            <div class="perf-track"><div class="perf-bar after" style="width:81.9%"></div></div>
            <span class="perf-value new">2.30 GB</span>
          </div>
          <p class="perf-delta">18% less</p>
        </div>
        <div>
          <span class="perf-label">CPU instructions</span>
          <div class="perf-pair">
            <div class="perf-track"><div class="perf-bar before" style="width:100%"></div></div>
            <span class="perf-value old">0.51T</span>
            <div class="perf-track"><div class="perf-bar after" style="width:81.0%"></div></div>
            <span class="perf-value new">0.41T</span>
          </div>
          <p class="perf-delta">19% fewer</p>
        </div>
      </div>
    </div>

    <div class="perf-row">
      <div class="perf-id">
        <p class="perf-name">chrome_crashpad_handler</p>
        <p class="perf-format">ELF x86-64</p>
        <p class="perf-scale"><span>6,092 functions</span><span>1.9 MB</span></p>
      </div>
      <div class="perf-metrics">
        <div>
          <span class="perf-label">Analysis time</span>
          <div class="perf-pair">
            <div class="perf-track"><div class="perf-bar before" style="width:100%"></div></div>
            <span class="perf-value old">32.8s</span>
            <div class="perf-track"><div class="perf-bar after" style="width:94.3%"></div></div>
            <span class="perf-value new">30.9s</span>
          </div>
          <p class="perf-delta">1.06&times; faster</p>
        </div>
        <div>
          <span class="perf-label">Peak memory</span>
          <div class="perf-pair">
            <div class="perf-track"><div class="perf-bar before" style="width:100%"></div></div>
            <span class="perf-value old">3.00 GB</span>
            <div class="perf-track"><div class="perf-bar after" style="width:67.6%"></div></div>
            <span class="perf-value new">2.03 GB</span>
          </div>
          <p class="perf-delta">32% less</p>
        </div>
        <div>
          <span class="perf-label">CPU instructions</span>
          <div class="perf-pair">
            <div class="perf-track"><div class="perf-bar before" style="width:100%"></div></div>
            <span class="perf-value old">0.96T</span>
            <div class="perf-track"><div class="perf-bar after" style="width:78.6%"></div></div>
            <span class="perf-value new">0.76T</span>
          </div>
          <p class="perf-delta">21% fewer</p>
        </div>
      </div>
    </div>

    <div class="perf-row">
      <div class="perf-id">
        <p class="perf-name">locationd</p>
        <p class="perf-format">Mach-O universal, x86-64 slice</p>
        <p class="perf-scale"><span>28,372 functions</span><span>19.0 MB</span></p>
      </div>
      <div class="perf-metrics">
        <div>
          <span class="perf-label">Analysis time</span>
          <div class="perf-pair">
            <div class="perf-track"><div class="perf-bar before" style="width:100%"></div></div>
            <span class="perf-value old">63.9s</span>
            <div class="perf-track"><div class="perf-bar after" style="width:64.8%"></div></div>
            <span class="perf-value new">41.4s</span>
          </div>
          <p class="perf-delta">1.54&times; faster</p>
        </div>
        <div>
          <span class="perf-label">Peak memory</span>
          <div class="perf-pair">
            <div class="perf-track"><div class="perf-bar before" style="width:100%"></div></div>
            <span class="perf-value old">6.06 GB</span>
            <div class="perf-track"><div class="perf-bar after" style="width:59.8%"></div></div>
            <span class="perf-value new">3.62 GB</span>
          </div>
          <p class="perf-delta">40% less</p>
        </div>
        <div>
          <span class="perf-label">CPU instructions</span>
          <div class="perf-pair">
            <div class="perf-track"><div class="perf-bar before" style="width:100%"></div></div>
            <span class="perf-value old">3.33T</span>
            <div class="perf-track"><div class="perf-bar after" style="width:83.8%"></div></div>
            <span class="perf-value new">2.79T</span>
          </div>
          <p class="perf-delta">16% fewer</p>
        </div>
      </div>
    </div>

    <div class="perf-row">
      <div class="perf-id">
        <p class="perf-name">ntoskrnl.exe</p>
        <p class="perf-format">PE32+ x86-64</p>
        <p class="perf-scale"><span>34,146 functions</span><span>12.8 MB</span></p>
      </div>
      <div class="perf-metrics">
        <div>
          <span class="perf-label">Analysis time</span>
          <div class="perf-pair">
            <div class="perf-track"><div class="perf-bar before" style="width:100%"></div></div>
            <span class="perf-value old">257s</span>
            <div class="perf-track"><div class="perf-bar after" style="width:49.6%"></div></div>
            <span class="perf-value new">128s</span>
          </div>
          <p class="perf-delta">2.02&times; faster</p>
        </div>
        <div>
          <span class="perf-label">Peak memory</span>
          <div class="perf-pair">
            <div class="perf-track"><div class="perf-bar before" style="width:100%"></div></div>
            <span class="perf-value old">8.78 GB</span>
            <div class="perf-track"><div class="perf-bar after" style="width:45.1%"></div></div>
            <span class="perf-value new">3.96 GB</span>
          </div>
          <p class="perf-delta">55% less</p>
        </div>
        <div>
          <span class="perf-label">CPU instructions</span>
          <div class="perf-pair">
            <div class="perf-track"><div class="perf-bar before" style="width:100%"></div></div>
            <span class="perf-value old">18.3T</span>
            <div class="perf-track"><div class="perf-bar after" style="width:47.0%"></div></div>
            <span class="perf-value new">8.57T</span>
          </div>
          <p class="perf-delta">53% fewer</p>
        </div>
      </div>
    </div>

    <div class="perf-row">
      <div class="perf-id">
        <p class="perf-name">libbinaryninjaui.so.1</p>
        <p class="perf-format">ELF x86-64 shared object</p>
        <p class="perf-scale"><span>43,957 functions</span><span>136.1 MB</span></p>
      </div>
      <div class="perf-metrics">
        <div>
          <span class="perf-label">Analysis time</span>
          <div class="perf-pair">
            <div class="perf-track"><div class="perf-bar before" style="width:100%"></div></div>
            <span class="perf-value old">76.4s</span>
            <div class="perf-track"><div class="perf-bar after" style="width:72.8%"></div></div>
            <span class="perf-value new">55.6s</span>
          </div>
          <p class="perf-delta">1.37&times; faster</p>
        </div>
        <div>
          <span class="perf-label">Peak memory</span>
          <div class="perf-pair">
            <div class="perf-track"><div class="perf-bar before" style="width:100%"></div></div>
            <span class="perf-value old">8.48 GB</span>
            <div class="perf-track"><div class="perf-bar after" style="width:93.2%"></div></div>
            <span class="perf-value new">7.90 GB</span>
          </div>
          <p class="perf-delta">7% less</p>
        </div>
        <div>
          <span class="perf-label">CPU instructions</span>
          <div class="perf-pair">
            <div class="perf-track"><div class="perf-bar before" style="width:100%"></div></div>
            <span class="perf-value old">3.26T</span>
            <div class="perf-track"><div class="perf-bar after" style="width:90.1%"></div></div>
            <span class="perf-value new">2.94T</span>
          </div>
          <p class="perf-delta">10% fewer</p>
        </div>
      </div>
    </div>

    <div class="perf-row">
      <div class="perf-id">
        <p class="perf-name">vmlinux 6.14</p>
        <p class="perf-format">ELF AArch64, with DWARF</p>
        <p class="perf-scale"><span>92,961 functions</span><span>511.8 MB</span></p>
      </div>
      <div class="perf-metrics">
        <div>
          <span class="perf-label">Analysis time</span>
          <div class="perf-pair">
            <div class="perf-track"><div class="perf-bar before" style="width:100%"></div></div>
            <span class="perf-value old">761s</span>
            <div class="perf-track"><div class="perf-bar after" style="width:46.2%"></div></div>
            <span class="perf-value new">352s</span>
          </div>
          <p class="perf-delta">2.16&times; faster</p>
        </div>
        <div>
          <span class="perf-label">Peak memory</span>
          <div class="perf-pair">
            <div class="perf-track"><div class="perf-bar before" style="width:100%"></div></div>
            <span class="perf-value old">17.29 GB</span>
            <div class="perf-track"><div class="perf-bar after" style="width:70.9%"></div></div>
            <span class="perf-value new">12.25 GB</span>
          </div>
          <p class="perf-delta">29% less</p>
        </div>
        <div>
          <span class="perf-label">CPU instructions</span>
          <div class="perf-pair">
            <div class="perf-track"><div class="perf-bar before" style="width:100%"></div></div>
            <span class="perf-value old">46.7T</span>
            <div class="perf-track"><div class="perf-bar after" style="width:48.4%"></div></div>
            <span class="perf-value new">22.6T</span>
          </div>
          <p class="perf-delta">52% fewer</p>
        </div>
      </div>
    </div>

    <div class="perf-row">
      <div class="perf-id">
        <p class="perf-name">chrome</p>
        <p class="perf-format">ELF x86-64, with DWARF</p>
        <p class="perf-scale"><span>950,042 functions</span><span>1.47 GB</span></p>
      </div>
      <div class="perf-metrics">
        <div>
          <span class="perf-label">Analysis time</span>
          <div class="perf-pair">
            <div class="perf-track"><div class="perf-bar before" style="width:100%"></div></div>
            <span class="perf-value old">1186s</span>
            <div class="perf-track"><div class="perf-bar after" style="width:49.3%"></div></div>
            <span class="perf-value new">584s</span>
          </div>
          <p class="perf-delta">2.03&times; faster</p>
        </div>
        <div>
          <span class="perf-label">Peak memory</span>
          <div class="perf-pair">
            <div class="perf-track"><div class="perf-bar before" style="width:100%"></div></div>
            <span class="perf-value old">43.85 GB</span>
            <div class="perf-track"><div class="perf-bar after" style="width:74.8%"></div></div>
            <span class="perf-value new">32.82 GB</span>
          </div>
          <p class="perf-delta">25% less</p>
        </div>
        <div>
          <span class="perf-label">CPU instructions</span>
          <div class="perf-pair">
            <div class="perf-track"><div class="perf-bar before" style="width:100%"></div></div>
            <span class="perf-value old">59.3T</span>
            <div class="perf-track"><div class="perf-bar after" style="width:64.7%"></div></div>
            <span class="perf-value new">38.3T</span>
          </div>
          <p class="perf-delta">35% fewer</p>
        </div>
      </div>
    </div>
  </div>

  <details class="perf-method">
    <summary>How this was measured</summary>
    <div class="perf-method-body">
      <dl>
        <dt>Machine</dt>
        <dd>AMD Ryzen 9 9950X (16 cores, 32 threads), 96&nbsp;GB RAM, Ubuntu 26.04. Measurements made while idle.</dd>
        <dt>Procedure</dt>
        <dd>Default headless analysis to completion including full decompilation, three runs per binary (one for Chrome), reporting the mean. Time is wall-clock analysis time; memory is peak resident set size.</dd>
      </dl>
    </div>
  </details>
</div>

<p>As you can see, across a representative corpus, 6.0 analyzes up to 2.16x faster than 5.3 while using as much as 55% less peak memory.</p>

<p>These gains come from many changes rather than any single optimization. There were dozens of smaller fixes, hundreds of hours of profiling, new tools developed to analyze memory usage, and Brian, Mark, Ryan, and others working to optimize the system. Nothing was sacred: many long-standing data structures and sections of code were critically examined for potential improvements.</p>

<h3 id="analysis-cache">Analysis Cache</h3>

<p>Binary Ninja maintains an analysis cache of analyzed functions. However, choosing when to re-analyze and when to cache can be tricky to get right from a performance perspective. With improved instrumentation and analysis, we were able to make much better use of the existing analysis cache while also fixing some bugs along the way.</p>

<h3 id="database-saving">Database Saving</h3>

<p>This is just the beginning as we’re planning to focus even more on save and load times in future releases. However, in 6.0, we’ve already improved both <a href="https://github.com/Vector35/binaryninja-api/issues/8085">memory usage</a> and time taken for saving, as well as fixed <a href="https://github.com/Vector35/binaryninja-api/issues/7678">a file size creep bug</a> where files could keep growing with repeated saves.</p>

<h2 id="mcp">MCP</h2>

<p>While, in a previous release, Tim and BK on the Sidekick team <a href="https://docs.sidekick.binary.ninja/guide/mcp_tools.html">added external MCP server support to Sidekick</a>, with Binary Ninja 6.0, we shipped a first-party <a href="https://docs.binary.ninja/guide/mcp.html">MCP server</a>. It’s “batteries included” for the LLM-using world. It can interact directly with the UI you are looking at or, for versions of the product with headless API support, can be used directly without the UI at all.</p>

<p>There are two variants. The GUI MCP server runs inside Binary Ninja, communicating over HTTP, and is included in all editions including <a href="/2026/09/03/binary-ninja-6.0-krypton.html#new-features-in-free">free</a>. The headless MCP server is a standalone <code class="language-plaintext highlighter-rouge">binaryninja_mcp</code> binary that communicates over stdio, and is included with Commercial and Ultimate on macOS and Linux. Native Windows packages don’t ship the headless binary yet. Use the built-in GUI MCP server there or run the Linux build under WSL. This is an unfortunate limitation due to Windows’ file system locking, where a running MCP server can corrupt or block an installation.</p>

<p>Both variants expose the same data and allow the same actions: opening files and databases, selecting BinaryViews, driving and waiting on analysis updates, a compact triage summary of a binary, program structure (entry points, segments, sections, symbols, imports, exports, relocations, data variables, and strings), raw memory reads, function inspection covering metadata, disassembly, Pseudo C, ILs, and many more useful properties. They can rename objects, create and apply types, and create data variables as well.</p>

<p>Turning on the GUI server is easy: enable <code class="language-plaintext highlighter-rouge">ui.mcp.enabled</code> in settings and restart to automatically start, <em>or</em> run <code class="language-plaintext highlighter-rouge">Plugins &gt; MCP &gt; Start Server</code> for one-off runs. With default settings it listens at <code class="language-plaintext highlighter-rouge">http://127.0.0.1:24642/mcp</code>, and <code class="language-plaintext highlighter-rouge">Plugins &gt; MCP &gt; Copy Connection Info</code> will hand you the exact URL and authorization header for your session, so you can paste it straight into your client. If you’d rather lock it down, set <code class="language-plaintext highlighter-rouge">ui.mcp.token</code> and clients will need to send a matching bearer token.</p>

<p>The <a href="https://docs.binary.ninja/guide/mcp.html#client-configuration-examples">documentation</a> has ready-to-paste configurations for Claude Desktop, Cursor, VS Code, and Codex, as well as much more information.</p>

<h2 id="binary-similarity">Binary Similarity</h2>

<p>Binary Similarity is, at heart, the task of noticing that the two functions in front of you are the same, except one has a cape and one wears glasses.</p>

<p>With 6.0, Mason created our Binary Similarity system for comparing two or more related binaries. It’s not a competing diffing engine to popular tools like BinDiff, Diaphora, or BSim. Rather, it’s a pluggable framework which can not only leverage multiple providers, but also allow you to integrate, compare, and do more with them than ever before.</p>

<p>We currently ship two providers: <a href="https://github.com/google/bindiff">Google BinDiff</a> (for finding structurally similar functions) and <a href="https://docs.binary.ninja/guide/warp.html">WARP</a> (for finding exact function matches). All providers report similarity and confidence, allowing you to review possible matches, render them side by side, and apply the available analysis information to the new binary.</p>

<p><img src="/blog/images/6.0-release/similarity-duck-graph.png" alt="A similarity result rendered in Graph view." class="image max-height-700" /></p>

<p>For example, when comparing two releases of a popular game, Binary Similarity quickly highlights the changes in <code class="language-plaintext highlighter-rouge">cGcFrontendPageShop::GenerateRepShopInventory</code>. Rendering the result keeps both versions in sync and highlights the differences, making it easy to identify patched logic.</p>

<p><img src="/blog/images/6.0-release/similarity-sky.png" alt="The changed game function rendered side by side." class="image max-height-700" /></p>

<p>Patch diffing is not the only use case. Often you have a heavily annotated binary whose annotations you want to port to a newer (or different) version. With Binary Similarity, we can automatically transfer annotations from one binary to another, saving time and effort.</p>

<p><img src="/blog/images/6.0-release/similarity-duck-original.png" alt="The original `main` function in the reference build." class="image max-height-700" /></p>

<div class="juxtapose max-height-700" style="margin-bottom: 1rem;" data-animate="true">
  <img data-label="After applying the match" src="/blog/images/6.0-release/similarity-duck-after.png" />
  <img data-label="Before applying the match" src="/blog/images/6.0-release/similarity-duck-before.png" />
</div>

<p>Of course, the UI is not the only way to use the new Binary Similarity functionality. This is Binary Ninja, after all: <em>everything</em> is pluggable and accessible via an API. The complete system is exposed through the <a href="https://api.binary.ninja/binaryninja.similarity-module.html">Python API</a>, <a href="https://api.binary.ninja/cpp/class_binary_ninja_1_1_similarity_session.html">C++ API</a>, and <a href="https://rust.binary.ninja/binaryninja/similarity/index.html">Rust API</a>, allowing you to <a href="https://docs.binary.ninja/guide/similarity.html#python-and-headless-usage">create and run sessions headlessly</a>.</p>

<p>Plugins can also register entirely new <a href="https://api.binary.ninja/binaryninja.similarity-module.html#binaryninja.similarity.SimilarityProviderType">providers</a> and <a href="https://api.binary.ninja/binaryninja.similarity-module.html#binaryninja.similarity.SimilaritySessionResolverType">resolvers</a>. Providers find possible matches, while resolvers choose which results to use (and can apply them automatically), so the system is not limited to WARP and BinDiff or to our built-in matching algorithm(s). In fact, the third-party <a href="https://github.com/matteyeux/binja-diff">binja diff</a> plugin, which wraps <a href="https://github.com/quarkslab/qbindiff">QBinDiff</a> by <a href="https://blog.quarkslab.com/qbindiff-a-modular-diffing-toolkit.html">Quarkslab</a>, already supports adding QBinDiff as a provider for a second opinion to BinDiff.</p>

<p class="notification is-primary"><strong>NOTE: Binary Similarity is only available in Ultimate</strong>.</p>

<p>For more information on configuring sessions, reviewing and applying results, or running it headlessly, see the <a href="https://docs.binary.ninja/guide/similarity.html">Binary Similarity documentation</a>. Our immediate roadmap includes new integrations and even our own novel matching implementation, so stay tuned!</p>

<h2 id="architectures-and-platforms">Architectures and Platforms</h2>

<h3 id="tms320c6x">TMS320C6x</h3>

<p>Brandon’s been on a DSP kick and adding those difficult-to-decompile architectures to Binary Ninja. First it was <a href="/2025/11/13/binary-ninja-5.2-io.html#hexagon">Hexagon</a> and, now with 6.0, it’s TMS320C6x.</p>

<p>Keep an eye out for an upcoming blog post with more details about all the behind-the-scenes changes and how we can now handle such a problematic architecture. In the meantime, all customers with current Ultimate support can update to a version with 19 first-party architectures!</p>

<p>Here’s a quick sneak peek for everyone else:</p>

<p><img src="/blog/images/6.0-release/tms320c6x-support.png" alt="Texas Instruments TMS320 C6x Support" class="image max-height-500" /></p>

<h3 id="multiple-global-pointers">Multiple Global Pointers</h3>

<p>Binary Ninja could previously track and allow users to override only a single global pointer register, but that doesn’t cut it for every architecture. TriCore, for example, uses four registers to point into different global data regions, and Binary Ninja can now track and override each of them independently. With accurate global pointer values available during analysis, references to global data resolve correctly and produce much cleaner decompilation.</p>

<p><img src="/blog/images/6.0-release/multiple-global-pointers.png" alt="Multiple Global Pointers" class="image max-height-500" /></p>

<h2 id="analysis">Analysis</h2>

<h3 id="improved-base-fast-analysis-mode">Improved BASE (Fast Analysis Mode)</h3>

<p>Introduced in <a href="/2024/05/21/automatically-identifying-base-addresses.html">a previous</a> post, BASE is our automated <a href="https://docs.binary.ninja/guide/index.html#4-base-address-detection-base">base address detection feature</a> built into all versions of Binary Ninja. With 6.0, it includes a new “sampling” mode, enabled by default, which can produce accurate results much faster. It’s especially useful for large files, though the previous IL Analysis Mode is still available when accuracy matters more than speed.</p>

<p><img src="/blog/images/6.0-release/fast-base.png" alt="Base Detection - IL Sampling Mode" class="image max-height-500" /></p>

<h3 id="calling-convention-refactor">Calling Convention Refactor</h3>

<p>One of our main thrusts going forward is better handling of language-specific decompilation. We’ve built <a href="/2024/11/20/4.2-frogstar.html#language-representations">language representation</a> features for that, and our <a href="https://docs.binary.ninja/dev/workflows.html">workflow</a> system lets us tweak the decompilation in many useful ways. But our type system, calling convention, and ILs likely need changes to fully support the most modern programming languages. Instead of sticking to just treating everything like C, we want to keep working toward language-specific support like we have with <a href="/2024/10/16/objectivec-update.html">Objective-C</a>.</p>

<p>To that end, in 6.0 Rusty refactored our calling convention system. We can now support structure returns and parameters which are used by a number of languages. Most of the changes you’ll see in 6.0 may seem minimal at face value, but actually unblock several future language-specific decompilation improvements that you should see in upcoming stable releases (or even sooner if you follow our development branch).</p>

<p>That said, we do ship two specific changes in 6.0. While the added Go and Pascal <a href="https://github.com/Vector35/binaryninja-api/commit/217b4a3361cbf62020658f12efb47b8fabb6a24d">calling conventions</a> don’t do much out of the box, when combined with a plugin like <a href="https://github.com/psifertex/delphinja">Delphinja</a>, you can get some much improved results since it includes type libraries and specific debug information parsing that can leverage the new convention!</p>

<div class="juxtapose max-height-700" style="margin-bottom: 1rem;" data-animate="true">
  <img data-label="After applying the plugin and calling convention" src="/blog/images/6.0-release/delphinja-after.png" />
  <img data-label="Before applying the plugin and calling convention" src="/blog/images/6.0-release/delphinja-before.png" />
</div>

<p>The Go calling convention support is in the core, but as we’re not yet processing the metadata available in <code class="language-plaintext highlighter-rouge">.gopclntab</code> sections and similar information, you won’t see any automatic changes yet. Keep an eye out for this in the next stable release!</p>

<h3 id="hlil_struct_initialize">HLIL_STRUCT_INITIALIZE</h3>

<p>A new <a href="https://github.com/Vector35/binaryninja-api/commit/eef36c8473e09064595ad68ff31ddff81580b5d3">IL instruction</a> and a system for <a href="https://github.com/Vector35/binaryninja-api/commit/eef36c8473e09064595ad68ff31ddff81580b5d3">initializer expressions</a> greatly simplify structure initializations, resulting in some very clean decompilation.</p>

<p><img src="/blog/images/6.0-release/struct-init.png" alt="Structure Initialization" class="image max-height-200" /></p>

<h3 id="type-fragments">Type Fragments</h3>

<p>Fragments from Krypton are bad news. Type fragments in Krypton are great news.</p>

<p>A <a href="https://docs.binary.ninja/guide/types/fragments.html">type fragment</a> represents a bitwise slice of a larger source type while that slice is carried in integer-like storage. When a calling convention passes pieces of a structure in registers, or an optimized inline <code class="language-plaintext highlighter-rouge">memcpy</code> copies a typed object in register-sized chunks, those pieces used to decay into integers and the connection back to the original object was lost. Type fragments preserve that relationship, tracking which bits of which source type a given register is holding as it flows through the program.</p>

<p>These are intermediate, in-flight types used by analysis rather than something you’ll define yourself, and they render in decompiled output using <code class="language-plaintext highlighter-rouge">__frag</code> notation (or <code class="language-plaintext highlighter-rouge">__frag_be</code> when the source is big-endian). Together with the <a href="/2026/09/03/binary-ninja-6.0-krypton.html#calling-convention-refactor">calling convention refactor</a> above, this means structures split across registers keep their types instead of just dissolving into integers.</p>

<div class="juxtapose max-height-700" style="margin-bottom: 1rem;" data-animate="true">
  <img data-label="After the 6.0 type fragment support" src="/blog/images/6.0-release/typefragment-after.png" />
  <img data-label="Before the 6.0 type fragment support" src="/blog/images/6.0-release/typefragment-before.png" />
</div>

<h2 id="scripting-and-extensions">Scripting and Extensions</h2>

<h3 id="python-313-and-linux">Python 3.13 and Linux</h3>

<p>We’ve been shipping a bundled Python in our macOS and Windows builds of Binary Ninja for a while now. Starting in 6.0, we ship this bundled Python with all builds on all platforms, including x86-64 and AArch64 Linux. This means that our support for third-party Linux distributions should be a bit more reliable since we don’t need to make assumptions about what’s installed by default.</p>

<p>While he was at it, Alex also bumped the included version to 3.13 to keep things a bit more modern. Our minimum supported version is still 3.10 if you require something older, however.</p>

<p>This does mean that if you were running the previously bundled version of Python and you switch, none of your plugin dependencies will be installed! The one-time <a href="/2026/09/03/binary-ninja-6.0-krypton.html#extension-manager">Plugin Migration</a> dialog will reinstall them for you.</p>

<h3 id="scripting-console">Scripting Console</h3>

<p>A small but noticeable quality-of-life improvement for those who do a lot of scripting: the scripting console now hints at individual parameters instead of just the prototype.</p>

<p><img src="/blog/images/6.0-release/params.png" alt="Scripting Console Parameter Hints" class="image max-height-300" /></p>

<h3 id="extension-manager">Extension Manager</h3>

<p>The Plugin Manager is dead, long live the Extension Manager! This change not only sets the groundwork for better plugin features, but also paves the way for native plugins and being able to install things other than plugins, like themes or type libraries. Almost half the team touched the extension manager code this release, it was truly a team effort.</p>

<p><img src="/blog/images/6.0-release/plugin-details.png" alt="Switching between installed versions of an extension" class="image max-height-300" /></p>

<p>Here are the main features you’ll see with the new Extension Manager:</p>

<ul>
  <li>You can choose which version of a plugin to install</li>
  <li>Dependency installation opens a dialog so you can see pip at work</li>
  <li>Conflicting dependencies have some auto-detection and resolution</li>
  <li>Plugin details are cached offline</li>
  <li>Plugins are more verbose about their status in details and the extension list</li>
  <li>The snippets plugin is shipped by default</li>
  <li>Plugins can be sorted by name, publication date, or most recently updated</li>
</ul>

<p><img src="/blog/images/6.0-release/plugin-sorting.png" alt="Sorting the extension list" class="image max-height-300" /></p>

<p>One heads-up if you’re updating: Extensions installed through the extension manager are stored differently on disk, so your first 6.0 launch will run a one-time migration. This will reinstall everything you had previously, dependencies included, and re-enable them when it’s done.</p>

<p>We also want to have a special mention to one of our summer interns Ashvika who did a ton of work to improve our <a href="https://extensions.binary.ninja">plugin ecosystem</a>. If you notice many more plugins with proper images and readmes, you can thank her for it!</p>

<p><img src="/blog/images/6.0-release/plugin-migration.png" alt="The one-time Plugin Migration dialog, listing BinSync for reinstall" class="image max-height-500" /></p>

<p>You’ll notice the new name in the API, too: The Python module is now <code class="language-plaintext highlighter-rouge">extensionmanager</code>, with a deprecation shim left behind.</p>

<h2 id="new-user-wizard">New User Wizard</h2>

<p>It’s hard to switch tools when you’re used to a particular workflow or hotkey, and it’s even harder to dig and find all the settings you might want to change in a new tool. New in 6.0 is a short three-step wizard. You choose a light or dark theme, a preferred experience, and a few privacy and network settings (automatic crash reports, automatic update checks, and online <a href="https://docs.binary.ninja/guide/warp.html">WARP</a>).</p>

<p>The middle step is for you if you’re arriving from another tool. Next to the Binary Ninja defaults, you can pick a Ghidra or IDA-Like experience. There are multiple differences among them, and the configuration lives in <a href="https://github.com/Vector35/binaryninja-api/tree/dev/docs/files"><code class="language-plaintext highlighter-rouge">docs/files</code></a> in the API repository - contributions are welcome.</p>

<p><img src="/blog/images/6.0-release/first-run-wizard.png" alt="Choosing a starting workflow preset" class="image max-height-500" /></p>

<p>If you want more information about what’s different compared to other tools, check out our <a href="https://docs.binary.ninja/guide/migration/index.html">migration guide</a>.</p>

<h2 id="debugger">Debugger</h2>

<p>Krypton gives you a much clearer picture of the process around the code you are debugging. The new <a href="https://docs.binary.ninja/guide/debugger/index.html#reading-the-target-memory-map">Debugger Memory Map</a> sidebar shows every mapped region reported by the debug adapter, including its address range, size, permissions, and name. Binary Ninja can also <a href="https://docs.binary.ninja/guide/debugger/index.html#the-debugger-memory-region">mirror those mappings as individual memory regions</a>, allowing <code class="language-plaintext highlighter-rouge">Find</code> to search mapped memory without trying to scan the entire address space. And when an address belongs to a library that was not part of the original analysis, you can now <a href="https://docs.binary.ninja/guide/debugger/index.html#loading-symbols-from-the-debugger-backend">load symbols from the debugger backend on demand</a>, either for one module or for all loaded modules. These are added as auto symbols, so they participate in analysis and annotations without overriding any names you have defined yourself.</p>

<p><img src="/blog/images/6.0-release/debugger-load-symbols.png" alt="Loading backend symbols from the Module widget's context menu" class="image max-height-300" /></p>

<ul>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/debugger/commit/cf3d774a0c65f45200d0cc88af3df47469378ace">double-click navigation</a> to a token’s runtime address during a debug session</li>
  <li><strong>Feature</strong>: Added the ability to go to the <a href="https://github.com/Vector35/debugger/issues/1123">previous/next register write</a> in TTD (Time Travel Debugging)</li>
  <li><strong>Improvement</strong>: Made the <a href="https://docs.binary.ninja/guide/debugger/dbgeng-ttd.html">WinDbg/TTD</a> version a setting instead of always downloading the latest</li>
  <li><strong>Improvement</strong>: Refined <a href="https://github.com/Vector35/debugger/commit/6a8e90e3769c5a0454aee6c1e86d53615da48592">double-click navigation</a> while debugging</li>
  <li><strong>Improvement</strong>: Skipped the <a href="https://docs.binary.ninja/guide/debugger/index.html#debug-adapter-settings-dialog">adapter settings dialog</a> on subsequent debug sessions</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/debugger/issues/1104">LLDB target creation</a> to use the executable path instead of the analyzed input file when debugging a shared library</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/debugger/commit/c3d5295ce59f21a196e0eafce60c1543fdaededc">breakpoint removal</a> after the debugger exits</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/debugger/issues/725">unreadable memory</a> during TTD when the readable region is smaller than a cache block</li>
  <li><strong>Fix</strong>: Fixed the <a href="https://github.com/Vector35/debugger/commit/4cf94e4c3bf0c254ef48cee1f79a3aa988c73baf">register cache</a> not being invalidated after a successful register write</li>
  <li><strong>Fix</strong>: Fixed incorrect <a href="https://github.com/Vector35/debugger/commit/144e4834da8f4223d206896a64943fb3205cd61a">module end addresses</a> on macOS with the LLDB adapter</li>
  <li><strong>Fix</strong>: Verified the <a href="https://github.com/Vector35/debugger/issues/1124">Authenticode signature</a> of the downloaded WinDbg MSI bundle</li>
</ul>

<h2 id="packaging-and-licensing">Packaging and Licensing</h2>

<h3 id="new-features-in-free">New Features in Free</h3>

<p>The most common request from <a href="/free/">Binary Ninja Free</a> users was for AArch64 support, and with 6.0 it’s finally here! The free edition now decompiles <code class="language-plaintext highlighter-rouge">armv8</code> (AArch64) in addition to <code class="language-plaintext highlighter-rouge">x86</code>, <code class="language-plaintext highlighter-rouge">x86_64</code>, and <code class="language-plaintext highlighter-rouge">armv7</code> (with Thumb2). That covers the overwhelming majority of binaries most people run into today, and we’re happy to make the free version even more useful.</p>

<p>Adding <code class="language-plaintext highlighter-rouge">armv8</code> also removed the reason we <a href="/2024/07/17/4.1-elysium.html#linux-arm-builds">held back</a> an ARM Linux build of Binary Ninja Free. So 6.0 ships a free installer for ARM Linux, available on the <a href="/free/">Binary Ninja Free download page</a>.</p>

<p>Armv8 isn’t the only thing new in Free for 6.0. Our new <a href="/2026/09/03/binary-ninja-6.0-krypton.html#mcp">MCP server</a> is included, so you can point your favorite LLM at Binary Ninja and let it use our analysis completely for free. Free keeps getting more powerful under a yellow sun.</p>

<p>Everything else stays the same. It’s still free for non-commercial and commercial evaluation uses. The remaining <a href="/free/#free-limitations">limitations</a> (no API or plugins and a reduced set of ILs) still apply. If you need any of our other architectures, the full breakdown of what ships in each edition lives on the <a href="/purchase/">purchase page</a>.</p>

<h3 id="sidekick-free">Sidekick Free</h3>

<p>In case you <a href="https://sidekick.binary.ninja/blog/introducing-sidekick-free/">missed it over on the Sidekick blog</a>, we recently launched <a href="https://sidekick.binary.ninja/free/">free Sidekick credits</a> for ALL Binary Ninja users with active support. You don’t need a credit card for a trial or to sign up. Just install the plugin and start using it. The included free credits refill every month.</p>

<h3 id="pricing-and-packaging">Pricing and Packaging</h3>

<p>As we outlined in our <a href="/2026/07/28/pricing-changes.html#enterprise-changes">6.0 pricing changes announcement</a>, collaboration is no longer included with Ultimate by default. It is now a per-seat add-on available for named, computer, and floating Ultimate licenses. You can choose to add it to only the seats that need shared projects, versioned check-ins, real-time chat, <a href="/enterprise/">and more</a>.</p>

<p>We have also removed the old minimum seat count needed to get access to the Binary Ninja Enterprise Server. Enterprise Servers are no longer licensed separately: customers with the collaboration add-on or floating Ultimate licenses can download and self-host as many servers as they need, wherever they need them.</p>

<h3 id="server-deployments">Server Deployments</h3>

<p>The new packaging also greatly improves how Enterprise Servers are managed. Instead of receiving a license for each server, you now create a server deployment in the <a href="https://portal.binary.ninja/">Binary Ninja Portal</a>. A deployment represents one server installation and belongs either to your account or to a team you manage.</p>

<p>From the portal’s new <a href="https://portal.binary.ninja/deployments">Server Deployments page</a>, you can create a deployment, assign floating licenses, and download a server bundle for your chosen platform, release channel, and version.
The server bundle includes everything needed to set up the server, and will look very familiar to those who have deployed Enterprise Servers in the past. If the floating licenses assigned to a deployment change, you can also download only a new license bundle without having to download the entire server bundle again.</p>

<p>Each floating license can be assigned to only one deployment at a time; if a multi-seat floating license needs to be divided across deployments, split it in the portal first, then assign each resulting license to the appropriate deployment.
Floating licenses can also be released from one deployment and reassigned to another. This lets you decide exactly how to distribute your floating seats across as many self-hosted deployments as your environment needs.</p>

<h1 id="open-source-contributions">Open-Source Contributions</h1>

<p>Special thanks to the following open-source contributors whose PRs were merged into this release:</p>

<ul>
  <li><a href="https://github.com/appleflyerv3">appleflyerv3</a> [<a href="https://github.com/Vector35/binaryninja-api/pull/8246">#8246</a>]</li>
  <li><a href="https://github.com/ArcaneNibble">ArcaneNibble</a> [<a href="https://github.com/Vector35/binaryninja-api/pull/7859">#7859</a>]</li>
  <li><a href="https://github.com/bloombit-dev">bloombit-dev</a> [<a href="https://github.com/Vector35/binaryninja-api/pull/8180">#8180</a>]</li>
  <li><a href="https://github.com/ChrisKader">ChrisKader</a> [<a href="https://github.com/Vector35/binaryninja-api/pull/8249">#8249</a>]</li>
  <li><a href="https://github.com/grant-h">grant-h</a> [<a href="https://github.com/Vector35/binaryninja-api/pull/8119">#8119</a>]</li>
  <li><a href="https://github.com/haileys">haileys</a> [<a href="https://github.com/Vector35/binaryninja-api/pull/8050">#8050</a>]</li>
  <li><a href="https://github.com/jonpalmisc">jonpalmisc</a> [<a href="https://github.com/Vector35/binaryninja-api/pull/8267">#8267</a>]</li>
  <li><a href="https://github.com/jrozner">jrozner</a> [<a href="https://github.com/Vector35/binaryninja-api/pull/8164">#8164</a>]</li>
  <li><a href="https://github.com/owah">owah</a> [<a href="https://github.com/Vector35/binaryninja-api/pull/8362">#8362</a>]</li>
  <li><a href="https://github.com/SmoothHacker">SmoothHacker</a> [<a href="https://github.com/Vector35/debugger/pull/1106">#1106</a>]</li>
  <li><a href="https://github.com/utkonos">utkonos</a> [<a href="https://github.com/Vector35/binaryninja-api/pull/7868">#7868</a>]</li>
  <li><a href="https://github.com/xitska">xitska</a> [<a href="https://github.com/Vector35/binaryninja-api/pull/8270">#8270</a>]</li>
  <li>endeavor [TMS320C6x Contributions]</li>
</ul>

<p>We appreciate your contributions!</p>

<h1 id="everything-else">Everything Else</h1>

<h2 id="analysis--core">Analysis / Core</h2>

<ul>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/fde1241ce928d38c2031c827ae0ddee5c6f5af0f"><code class="language-plaintext highlighter-rouge">abs</code>, <code class="language-plaintext highlighter-rouge">min</code></a>, and <code class="language-plaintext highlighter-rouge">max</code> <a href="https://docs.binary.ninja/dev/bnil-llil.html#the-arithmetic-logical-instructions">IL instructions</a></li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/d592ed6dafbb134553bf3a0b8ee70ff7f2049aba"><code class="language-plaintext highlighter-rouge">bswap</code>, <code class="language-plaintext highlighter-rouge">popcnt</code>, <code class="language-plaintext highlighter-rouge">clz</code>, <code class="language-plaintext highlighter-rouge">ctz</code>, <code class="language-plaintext highlighter-rouge">cls</code></a> and <code class="language-plaintext highlighter-rouge">rbit</code> <a href="https://docs.binary.ninja/dev/bnil-overview.html#bitwise-operations">instructions</a></li>
  <li><strong>Feature</strong>: Added an <a href="https://github.com/Vector35/binaryninja-api/commit/d9fd7a652dad9a36745bfbed3242f26c7d0301e5">SSA instruction for partial variable writes in HLIL</a></li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/8e7535e92fbb4305232eb19405f1d738437dcf4b">support for loading local stack variables</a> from <a href="https://docs.binary.ninja/guide/types/debuginfo.html#pdb-notes">PDB debug info</a></li>
  <li><strong>Feature</strong>: Added type convergence detection to prevent non-converging type inference</li>
  <li><strong>Improvement</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/issues/8278"><code class="language-plaintext highlighter-rouge">wmain</code> to <code class="language-plaintext highlighter-rouge">analysis.mainFunctionDetection.mainSymbols</code></a> so navigate-to-main also finds <code class="language-plaintext highlighter-rouge">wmain</code></li>
  <li><strong>Improvement</strong>: Added a <a href="https://github.com/Vector35/binaryninja-api/commit/1349246757ec6d7002407c2f89e40819293156e8">fast-fail to the Itanium RTTI parser</a> for large unbacked sections</li>
  <li><strong>Improvement</strong>: Added an <a href="https://github.com/Vector35/binaryninja-api/commit/f49bc8fd49477549ea4b36992f62b968921aa217">MLIL analysis pass to better separate partial writes</a> when the upper bits are unused</li>
  <li><strong>Improvement</strong>: Capped recursive function pointer type growth to a deterministic, parameter less spelling</li>
  <li><strong>Improvement</strong>: Improved <a href="https://github.com/Vector35/binaryninja-api/commit/71b1c61391c0b32dd19053bfcaf51bbd67f0a642">PDB import to collect locals and parameters</a> from blocks contained in a <code class="language-plaintext highlighter-rouge">FrameProcedure</code></li>
  <li><strong>Improvement</strong>: Improved <a href="https://docs.binary.ninja/guide/index.html#8-inline-during-analysis">function inlining</a> to handle nonstandard return registers</li>
  <li><strong>Improvement</strong>: Improved <a href="https://github.com/Vector35/binaryninja-api/commit/0498fe8cc36075829deeebb919a57150d1ff9a44">recovery of <code class="language-plaintext highlighter-rouge">sp</code>-based locals during PDB import</a></li>
  <li><strong>Improvement</strong>: Improved the accuracy of the <code class="language-plaintext highlighter-rouge">pvs</code> tooltip across all ILs</li>
  <li><strong>Improvement</strong>: Introduced <code class="language-plaintext highlighter-rouge">BiDiReferenceMap</code> and used it for the code, data and type reference indices, unifying their previously separate forward and reverse halves</li>
  <li><strong>Improvement</strong>: Preserved <a href="https://docs.binary.ninja/dev/outlining.html">outlined</a> strings with inferred <code class="language-plaintext highlighter-rouge">typedef</code>s</li>
  <li><strong>Improvement</strong>: Refined type convergence detectors</li>
  <li><strong>Improvement</strong>: Simplified <code class="language-plaintext highlighter-rouge">clz(x) u&gt;&gt; log2(W)</code> to <code class="language-plaintext highlighter-rouge">x == 0</code> in HLIL</li>
  <li><strong>Improvement</strong>: Used variable <a href="https://docs.binary.ninja/dev/concepts.html#static-single-assignment-basics">SSA</a> instead of memory SSA for direct access to array variables or structure fields in HLIL</li>
  <li><strong>Improvement</strong>: <a href="https://github.com/Vector35/binaryninja-api/commit/d46c79b22ff78cfff7c907acaae1ccba2e5b3580">Wired structured demangler simplification</a> for stdlib templates through the core</li>
  <li><strong>Fix</strong>: Fixed HLIL SSA loop condition <code class="language-plaintext highlighter-rouge">phi</code> expression mappings</li>
  <li><strong>Fix</strong>: Fixed HLIL SSA memory versioning for aliased partial writes and initializers</li>
  <li><strong>Fix</strong>: Fixed HLIL SSA missing a memory version increment for nested structures written through a pointer</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/5151">HLIL null comparisons dropping pointer offsets</a></li>
  <li><strong>Fix</strong>: Fixed IL for functions that referenced an address before a data variable was defined there, requiring re-analysis when the variable’s type changed</li>
  <li><strong>Fix</strong>: Fixed LLIL SSA to preserve register stack outputs</li>
  <li><strong>Fix</strong>: Fixed MLIL stack offsets not being reloaded correctly through local variables</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/84d66dc7e6244e6ef78ebb3a2aa24b57a6ed4345">PDB import</a> to only adjust stack-pointer-relative locals on <code class="language-plaintext highlighter-rouge">x86_64</code></li>
  <li><strong>Fix</strong>: Fixed <a href="https://api.binary.ninja/binaryninja.filemetadata-module.html#binaryninja.filemetadata.FileMetadata.original_filename"><code class="language-plaintext highlighter-rouge">original_filename</code></a> purge option not clearing identifying information from the <code class="language-plaintext highlighter-rouge">display_name</code> and virtual path fields</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/8327">case-insensitive search</a> not matching strings with different casing</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/8358">custom string types displaying non-ASCII characters as escaped UTF bytes</a> instead of the decoded text</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/1605">demangling of certain mangled Microsoft <code class="language-plaintext highlighter-rouge">x86_64</code> symbols</a> that were previously left unresolved</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/5151">incorrect HLIL translation</a> of pointer arithmetic involving <code class="language-plaintext highlighter-rouge">lea</code> that produced bogus comparisons like <code class="language-plaintext highlighter-rouge">this != -0x10</code></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/7443">malformed HLIL structure accessor</a> generated when applying a structure type to a variable computed with consecutive <code class="language-plaintext highlighter-rouge">adds</code> instructions</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/5992">scattered return values</a> not being combined correctly in MLIL/HLIL when a function’s return type is wider than a single return register</li>
  <li><strong>Fix</strong>: Fixed <a href="https://docs.binary.ninja/guide/index.html#find"><code class="language-plaintext highlighter-rouge">Find in HLIL</code></a> missing matches when HLIL line addresses are non-monotonic</li>
  <li><strong>Fix</strong>: Fixed <code class="language-plaintext highlighter-rouge">GetTypeForAccess</code> returning incorrect fragments for struct accesses spanning multiple fields</li>
  <li><strong>Fix</strong>: Fixed a <a href="https://github.com/Vector35/binaryninja-api/issues/8113">crash caused by deep mutual recursion</a> between <a href="https://api.binary.ninja/cpp/group__architectures.html#acf8c5e71910d6db19fac70572b225de3"><code class="language-plaintext highlighter-rouge">DefaultLiftFunction</code></a> and <a href="https://api.binary.ninja/cpp/class_binary_ninja_1_1_function_lifter_context.html#aea0a57c16a2ba4905b53c3cb76d95e75"><code class="language-plaintext highlighter-rouge">CheckForInlinedCall</code></a> when lifting deeply nested inlined calls</li>
  <li><strong>Fix</strong>: Fixed a <a href="https://github.com/Vector35/binaryninja-api/issues/7298">deadlock</a> causing UI freezes when analysis was running while many types were being created</li>
  <li><strong>Fix</strong>: Fixed a <a href="https://github.com/Vector35/binaryninja-api/issues/8230">stack overflow crash in the GNU3/MSVC demanglers</a> when demangling deeply recursive crafted names</li>
  <li><strong>Fix</strong>: Fixed a crash caused by cycles in the GNU3 demangler</li>
  <li><strong>Fix</strong>: Fixed a crash from malformed LLIL indirect branch targets</li>
  <li><strong>Fix</strong>: Fixed a <a href="https://github.com/Vector35/binaryninja-api/commit/75c344dcea30b1beb5680e46a7557c26fd7286e4">crash from unbounded recursion during function inlining</a> when two functions directly call each other</li>
  <li><strong>Fix</strong>: Fixed a few copy assignment operators to correctly handle self-assignment</li>
  <li><strong>Fix</strong>: Fixed a potential divide by zero in alignment checks</li>
  <li><strong>Fix</strong>: Fixed a race condition in <code class="language-plaintext highlighter-rouge">AddDataReferences</code> that could crash due to a missing lock</li>
  <li><strong>Fix</strong>: Fixed a <a href="https://github.com/Vector35/binaryninja-api/commit/871ae4542f4af914379c907666cb0fbe20658a7a">use-after-free in the GNU3 demangler</a> when expanding a template parameter pack</li>
  <li><strong>Fix</strong>: Fixed a use-after-free involving custom function architecture context</li>
  <li><strong>Fix</strong>: Fixed a use-after-free when a function was added to a component and its symbol was retired in the same batch</li>
  <li><strong>Fix</strong>: Fixed addition of signed range <a href="https://api.binary.ninja/binaryninja.variable-module.html#binaryninja.variable.PossibleValueSet"><code class="language-plaintext highlighter-rouge">PossibleValueSet</code></a>s</li>
  <li><strong>Fix</strong>: Fixed an assertion failure caused by using a variable ID where a variable index was expected</li>
  <li><strong>Fix</strong>: Fixed an out-of-range crash in symbol name truncation used by the disassembly text renderer</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/4e6453c7609bbea86c172f4df2f3aa3a3429677f">calculation of <code class="language-plaintext highlighter-rouge">struct</code> bit field member offsets</a> during PDB import</li>
  <li><strong>Fix</strong>: Fixed calculation of addition of two <code class="language-plaintext highlighter-rouge">UnsignedRange</code> values when both start and end overflow</li>
  <li><strong>Fix</strong>: Fixed calculation of the addition of two identical <code class="language-plaintext highlighter-rouge">PVS</code> ranges</li>
  <li><strong>Fix</strong>: Fixed crashes from a null <a href="https://api.binary.ninja/cpp/group___u_i_types.html#ga8406e1453c23b90bfc1db83b01bb8f17"><code class="language-plaintext highlighter-rouge">BinaryViewRef</code></a> when <a href="https://api.binary.ninja/cpp/group__filemetadata.html#a5cc722817efad734098e659d75724c8e"><code class="language-plaintext highlighter-rouge">GetViewOfType</code></a> raced with view removal</li>
  <li><strong>Fix</strong>: Fixed creation of <a href="https://api.binary.ninja/binaryninja.variable-module.html#binaryninja.variable.Variable"><code class="language-plaintext highlighter-rouge">Variable</code></a>s that could not be represented in their compact internal representation</li>
  <li><strong>Fix</strong>: Fixed creation of <code class="language-plaintext highlighter-rouge">void</code> data variables at call targets that had not yet been typed</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/4283">demangling of symbols in binaries built</a> with MSVC’s <code class="language-plaintext highlighter-rouge">/d2FH4</code> flag</li>
  <li><strong>Fix</strong>: Fixed detection of <a href="https://docs.binary.ninja/dev/concepts.html#working-with-strings">long strings</a></li>
  <li><strong>Fix</strong>: Fixed function type propagation to callers when a committed type change only affected confidence</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/5a7ab29fcf3f8389e1546ec7db0819cc77c1dfc9">handling of demangled results with no type information</a></li>
  <li><strong>Fix</strong>: Fixed incoming but resolved partial accesses being incorrectly treated as parameters</li>
  <li><strong>Fix</strong>: Fixed indirect stack offset loads in MLIL</li>
  <li><strong>Fix</strong>: Fixed invalid IL instruction access in <a href="https://api.binary.ninja/binaryninja.enums-module.html#binaryninja.enums.MediumLevelILOperation.MLIL_STORE_STRUCT_SSA"><code class="language-plaintext highlighter-rouge">MLIL_STORE_STRUCT_SSA</code></a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/7976">missing symbol name for <code class="language-plaintext highlighter-rouge">__chkstk</code></a> and other compiler-inserted functions in PE binaries</li>
  <li><strong>Fix</strong>: Fixed non-deterministic lifted IL for no-return tail calls</li>
  <li><strong>Fix</strong>: Fixed recursive function pointer detection misclassifying refined callbacks as growth</li>
  <li><strong>Fix</strong>: Fixed removal of composite parameter variables when they appeared unused</li>
  <li><strong>Fix</strong>: Fixed speculative data variable widths depending on function analysis order when two functions access the same address with different widths</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/4738">stack adjustment analysis to treat an empty value as <code class="language-plaintext highlighter-rouge">0</code></a></li>
  <li><strong>Fix</strong>: Fixed stack propagation through pointer <code class="language-plaintext highlighter-rouge">typedef</code>s</li>
  <li><strong>Fix</strong>: Fixed the <a href="https://github.com/Vector35/binaryninja-api/issues/5920">demangler</a> not creating types referenced from demangled names that don’t already exist</li>
  <li><strong>Fix</strong>: Fixed the <a href="https://github.com/Vector35/binaryninja-api/issues/8233">default location not updating</a> when changing the type of a return value</li>
  <li><strong>Fix</strong>: Fixed the string-finding analysis pass overwriting existing typed data variables</li>
  <li><strong>Fix</strong>: Fixed two bugs caused by function return values being unintentionally discarded</li>
  <li><strong>Fix</strong>: Fixed type propagation dropping <code class="language-plaintext highlighter-rouge">typedef</code>s during normalization</li>
  <li><strong>Fix</strong>: <a href="https://github.com/Vector35/binaryninja-api/issues/7204">Marked the <code class="language-plaintext highlighter-rouge">err</code> family of libc functions as <code class="language-plaintext highlighter-rouge">noreturn</code></a> in the <a href="https://docs.binary.ninja/dev/typelibraries.html">type library</a>, preventing bad disassembly after calls to them</li>
</ul>

<h2 id="performance">Performance</h2>

<ul>
  <li><strong>Improvement</strong>: Improved <a href="https://github.com/Vector35/binaryninja-api/commit/99160866ff3a335b172bc4cf2b820f893cab867c">performance of loading ELF binaries</a> with many sections not mapped into the address space</li>
  <li><strong>Improvement</strong>: Improved component tree performance</li>
  <li><strong>Improvement</strong>: Improved <a href="https://github.com/Vector35/binaryninja-api/commit/01ab3ad8dc144a4962831aaa4296cd8965dba1ef">performance of <code class="language-plaintext highlighter-rouge">IsELFDataRelocation</code> for <code class="language-plaintext highlighter-rouge">armv7</code></a> by using a switch instead of <code class="language-plaintext highlighter-rouge">std::map</code></li>
  <li><strong>Improvement</strong>: Improved performance of string annotation detection by skipping constants that aren’t mapped addresses</li>
  <li><strong>Improvement</strong>: Improved performance of string detection by eliminating unnecessary allocations</li>
  <li><strong>Improvement</strong>: Improved <a href="https://github.com/Vector35/binaryninja-api/commit/fe79d8451cfad684e01e4e7b784e647c972c8921">symbol throughput</a> by removing non-demangling <a href="https://api.binary.ninja/cpp/group__binaryview.html#class_binary_ninja_1_1_symbol_queue"><code class="language-plaintext highlighter-rouge">SymbolQueue</code></a> consumers</li>
  <li><strong>Improvement</strong>: <a href="https://github.com/Vector35/binaryninja-api/commit/6c34643b639607d7c0a652300bbdbc261fbe2388">Used a custom allocator for C++ containers</a> in the free edition</li>
  <li><strong>Fix</strong>: Cached <a href="https://github.com/Vector35/binaryninja-api/commit/18dc4ef025d08decdcaadba7168fc9c714f61899">log row size hints</a> to keep the <a href="https://docs.binary.ninja/guide/index.html#logs">log view</a> responsive under heavy logging</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/c6ba779fcc0406380778892db6fca5789ca37bf8">memory leaks</a> in the Python and Rust APIs</li>
  <li><strong>Fix</strong>: Fixed a memory leak of <a href="https://api.binary.ninja/binaryninja.datarender-module.html#binaryninja.datarender.DataRenderer"><code class="language-plaintext highlighter-rouge">DataRenderer</code></a> instances</li>
  <li><strong>Fix</strong>: Fixed several crashes that occurred when loading a database under low free memory conditions</li>
</ul>

<h2 id="ui">UI</h2>

<ul>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/issues/7390"><code class="language-plaintext highlighter-rouge">Create Struct Member at Offset</code> to the Type View</a></li>
  <li><strong>Feature</strong>: Added a <a href="https://github.com/Vector35/binaryninja-api/commit/88833c4256517df042d72136e6ad332e88a7b53e">hover preview for extern symbols</a> that includes type information</li>
  <li><strong>Feature</strong>: Added a <a href="https://github.com/Vector35/binaryninja-api/issues/3581">context menu action to remove tags</a></li>
  <li><strong>Feature</strong>: Added a <a href="https://github.com/Vector35/binaryninja-api/commit/5da9c9ba36985d8c008f07b157dbd2cec86303d4">description column to the <code class="language-plaintext highlighter-rouge">Project Browser</code></a></li>
  <li><strong>Feature</strong>: Added a <a href="https://github.com/Vector35/binaryninja-api/commit/8f2e99d1b6e814fcf7b9142889b7f2dfab5dd94e">function signature table to the edit function dialog</a></li>
  <li><strong>Feature</strong>: Added a <a href="https://github.com/Vector35/binaryninja-api/commit/c2f0d5d56cbbed3cba8115173f91e5a1b2c1e6cd">new UI for array-style settings</a></li>
  <li><strong>Feature</strong>: Added a <a href="https://github.com/Vector35/binaryninja-api/commit/1ead182421ff48240b77b04c0e9ac3c46b236eac">setting to control outline visibility</a></li>
  <li><strong>Feature</strong>: Added an <a href="https://github.com/Vector35/binaryninja-api/commit/297a98bff289ecde90d808f6538c2c5edf804af6">argument assist popup when typing function calls</a></li>
  <li><strong>Feature</strong>: Added an option to disable <code class="language-plaintext highlighter-rouge">Snippets</code></li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/ea603944bad1111ad6ae2c9a44fe50854955bdba">optional headers to sidebar widgets</a></li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/44ffb5d334d187e44a1cba32aa9bd6f3d29d42c0">optional size hints for splitters</a></li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/2430a9f05647d9e8ef9546c304cb362866acbcc2">support for custom data in flow graphs</a></li>
  <li><strong>Feature</strong>: Added support for diagonal scrolling in <a href="https://docs.binary.ninja/guide/index.html#graph-view">graph view</a></li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/989bbc8602371beadcadd99e49d6d69152f97e0d">support for extensible filter actions in the UI</a></li>
  <li><strong>Feature</strong>: Added the ability to change the scrollbar width</li>
  <li><strong>Feature</strong>: Grouped <a href="https://github.com/Vector35/binaryninja-api/commit/8ed744a615909ac4bec2bc6dd92cf5cb0485cf07">extern symbols by originating library</a> in <a href="https://docs.binary.ninja/guide/index.html#linear-view">Linear View</a> for Mach-O and PE binaries</li>
  <li><strong>Feature</strong>: <a href="https://github.com/Vector35/binaryninja-api/commit/19431d8015f65e7dbf50699375ab7c1e4ab309c9">Open sourced all default themes and added an alpha channel</a> to colors in <a href="https://docs.binary.ninja/dev/themes.html#theme-file-structure"><code class="language-plaintext highlighter-rouge">.bntheme</code> files</a></li>
  <li><strong>Improvement</strong>: <a href="https://github.com/Vector35/binaryninja-api/commit/ac359f8bcbbb64c9c89a821bb65879178815ce37">Accepted a lone <code class="language-plaintext highlighter-rouge">?</code> as a full-byte wildcard</a> in FlexHex search</li>
  <li><strong>Improvement</strong>: Added <code class="language-plaintext highlighter-rouge">wmain</code> to the list of entry point names recognized by the <a href="https://docs.binary.ninja/guide/settings.html#settings-reference">navigate to main setting</a></li>
  <li><strong>Improvement</strong>: Added a <a href="https://github.com/Vector35/binaryninja-api/commit/c60fb1379399825cc46e3be5947e8d0faf970723">helper for background sorting</a> and filtering of flat UI models</li>
  <li><strong>Improvement</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/9f9ec1403b215743a45dd3f50cbd1683143842de">horizontal scrolling</a> to the <a href="https://docs.binary.ninja/guide/index.html#history">History View</a></li>
  <li><strong>Improvement</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/issues/7093">horizontal scrolling to the Stack View</a></li>
  <li><strong>Improvement</strong>: Added the <a href="https://github.com/Vector35/binaryninja-api/commit/5bd3e607140dfcf6e3b08ca28749015e629c16c3">ability to hide columns in the project browser</a></li>
  <li><strong>Improvement</strong>: Allowed the <a href="https://docs.binary.ninja/guide/index.html#command-palette">command palette</a> to search project files by their full project path (e.g. <code class="language-plaintext highlighter-rouge">Project/File.exe</code>)</li>
  <li><strong>Improvement</strong>: <a href="https://github.com/Vector35/binaryninja-api/commit/1699a201a555c77ce4d7a29565eede638714dfee">Dispatched token double-clicks to plugins in linear</a> and graph views</li>
  <li><strong>Improvement</strong>: Displayed the external library name in the sticky header in linear view when many symbols are imported from the same library</li>
  <li><strong>Improvement</strong>: Hid the relative address in the <a href="https://github.com/Vector35/binaryninja-api/issues/7915">goto dialog</a> when it is not needed</li>
  <li><strong>Improvement</strong>: Improved <a href="https://github.com/Vector35/binaryninja-api/commit/4c278a57b59c4b8e913d17b47bc4828659b32659"><code class="language-plaintext highlighter-rouge">Display As</code> and type toggle behavior in the UI</a></li>
  <li><strong>Improvement</strong>: Improved <a href="https://github.com/Vector35/binaryninja-api/commit/0e4c8bbd310e404e6f16ed3bd2a0afaaf3a59298">default highlighting and fixed tab order</a></li>
  <li><strong>Improvement</strong>: Improved <a href="https://github.com/Vector35/binaryninja-api/commit/2ca70e1d23e2a344a77d29d0b12d9a69fb977f5f">rendering of tokenized text views</a></li>
  <li><strong>Improvement</strong>: Improved <a href="https://github.com/Vector35/binaryninja-api/commit/162b406ea28aa5bacc34a00745d8780bcbf58753">syntax highlighting for code blocks</a></li>
  <li><strong>Improvement</strong>: Improved <a href="https://github.com/Vector35/binaryninja-api/issues/4519">toggling of integer display signedness</a></li>
  <li><strong>Improvement</strong>: Made the command palette also look up <a href="https://api.binary.ninja/cpp/group__action.html#struct_u_i_action"><code class="language-plaintext highlighter-rouge">UIAction</code></a> aliases</li>
  <li><strong>Improvement</strong>: <a href="https://github.com/Vector35/binaryninja-api/commit/cb22b18b747aec488a63781a87a3a99ab7f38b27">Normalized theme handling and added support</a> for stylesheets specified as arrays</li>
  <li><strong>Improvement</strong>: <a href="https://github.com/Vector35/binaryninja-api/commit/19431d8015f65e7dbf50699375ab7c1e4ab309c9">Released all default UI themes as open source</a></li>
  <li><strong>Improvement</strong>: <a href="https://github.com/Vector35/binaryninja-api/issues/8326">Sorted Memory Map segments and sections numerically</a> by address</li>
  <li><strong>Improvement</strong>: Sorted <a href="https://github.com/Vector35/binaryninja-api/commit/23f619a047ff754eafb84a6ec5f666bbe9e47711">switch blocks</a> in graph view by case number</li>
  <li><strong>Fix</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/issues/5068">missing copy shortcuts</a></li>
  <li><strong>Fix</strong>: <a href="https://github.com/Vector35/binaryninja-api/commit/c7d51006ea8380c82c64650ad148311b7541d745">Darkened string color in the <code class="language-plaintext highlighter-rouge">classic</code> theme</a></li>
  <li><strong>Fix</strong>: Fixed Linear view navigation to data added since the last refresh</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/7392">Linear View losing the current navigation position</a> when word wrapping shifted line layout after toggling the sidebar</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/8137">Stack View allowing single-item actions when multiple items were selected</a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/8001">Symbol view folders re-expanding</a> after being collapsed</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/8352"><code class="language-plaintext highlighter-rouge">ViewFrame::navigate</code></a> unconditionally raising and activating the window, causing focus to be stolen when reverting an undo action</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/617c10d3cb0a9b9bad112c79c85384c08c22c98e">context menus for calls</a> when the call target is <a href="https://api.binary.ninja/binaryninja.enums-module.html#binaryninja.enums.HighLevelILOperation.HLIL_IMPORT"><code class="language-plaintext highlighter-rouge">HLIL_IMPORT</code></a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/8240">crash in the Add Type Library dialog</a> when canceling without selecting a platform</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/7262">incorrect possible value set display at MLIL</a> that showed <a href="https://api.binary.ninja/binaryninja.variable-module.html#binaryninja.variable.PossibleValueSet.undetermined"><code class="language-plaintext highlighter-rouge">undetermined</code></a> even though the correct values were available</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/8115">stack view</a> only allowing selection of the first item when multiple items share the same offset</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/8306">zero-sized fields no longer showing up in the UI</a></li>
  <li><strong>Fix</strong>: Fixed a crash caused by a null pointer in <code class="language-plaintext highlighter-rouge">setHighlightToken</code></li>
  <li><strong>Fix</strong>: Fixed a crash that could occur when displaying the <a href="https://docs.binary.ninja/guide/types/typelibraries.html">Type Library Explorer</a></li>
  <li><strong>Fix</strong>: Fixed a crash when double-clicking a function header in linear view</li>
  <li><strong>Fix</strong>: Fixed a few unintentionally hardcoded colors to use themed colors instead</li>
  <li><strong>Fix</strong>: Fixed a lock inversion in the <a href="https://docs.binary.ninja/guide/types/basictypes.html#types-view">type browser</a></li>
  <li><strong>Fix</strong>: Fixed a <a href="https://github.com/Vector35/binaryninja-api/issues/8175">scoring bug in the command palette</a></li>
  <li><strong>Fix</strong>: Fixed a strict weak ordering violation in the <a href="https://api.binary.ninja/cpp/group__options.html#class_options_dialog"><code class="language-plaintext highlighter-rouge">OptionsDialog</code></a> view sort comparator</li>
  <li><strong>Fix</strong>: Fixed a threading issue when saving navigation history</li>
  <li><strong>Fix</strong>: Fixed auto symbols shadowing user-defined symbols in the component tree</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/7182">content being lost when resizing a view</a></li>
  <li><strong>Fix</strong>: Fixed crash in the UI when the base structure or member type of a named type reference could not be resolved</li>
  <li><strong>Fix</strong>: Fixed dropping files or folders onto the project table</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/4eea1cb6e5775cb80dc737cfb763010872102c9b">horizontal scrolling artifacts</a></li>
  <li><strong>Fix</strong>: Fixed inaccurate <a href="https://github.com/Vector35/binaryninja-api/issues/8133">possible value set tooltip</a> for variables outside of MLIL SSA</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/6623">incorrect text shown when undefining a type or field</a></li>
  <li><strong>Fix</strong>: Fixed line wrap width calculation to stop using view width, which the UI could not adapt to without significant rework</li>
  <li><strong>Fix</strong>: Fixed multi-line form dialog inputs forcing a minimum width that caused unwanted horizontal scrolling</li>
  <li><strong>Fix</strong>: Fixed navigation raising and activating the wrong window when using detached <a href="https://docs.binary.ninja/guide/index.html#the-sidebar">sidebars</a></li>
  <li><strong>Fix</strong>: Fixed tab text and tooltip not refreshing to show updated display names until the next UI event</li>
  <li><strong>Fix</strong>: Fixed the <a href="https://github.com/Vector35/binaryninja-api/issues/5342">Settings <code class="language-plaintext highlighter-rouge">Resource</code> dropdown</a> to list each open tab separately instead of collapsing tabs of the same file into one entry</li>
  <li><strong>Fix</strong>: Fixed the <a href="https://docs.binary.ninja/guide/index.html#symbols">Symbols view</a> to respect collapsed folders during navigation and selection changes</li>
  <li><strong>Fix</strong>: Fixed the <a href="https://api.binary.ninja/binaryninja.workflow-module.html#binaryninja.workflow.Workflow"><code class="language-plaintext highlighter-rouge">Workflow</code></a> view incorrectly accepting navigation requests it couldn’t handle, preventing it from acting as a catch-all navigation sink</li>
  <li><strong>Fix</strong>: Fixed the <a href="https://github.com/Vector35/binaryninja-api/issues/8063">container browser and universal architecture selector</a> to use the project file name instead of the file metadata name</li>
  <li><strong>Fix</strong>: Fixed the <a href="https://github.com/Vector35/binaryninja-api/issues/8059">symbol widget</a> not showing all symbols defined at the same address</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/8309">truncation of file paths in the triage view</a></li>
  <li><strong>Fix</strong>: Improved <a href="https://github.com/Vector35/binaryninja-api/commit/0e4c8bbd310e404e6f16ed3bd2a0afaaf3a59298">default highlighting and fixed tab key order</a> in array settings UI</li>
  <li><strong>Fix</strong>: Restored the <a href="https://github.com/Vector35/binaryninja-api/issues/8257">placeholder helper text</a> in the <a href="https://docs.binary.ninja/guide/types/typeimportexport.html#import-header-file"><code class="language-plaintext highlighter-rouge">Create Types from C Source</code></a> dialog</li>
</ul>

<h2 id="architectures-and-platforms-1">Architectures and Platforms</h2>

<ul>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/f8f365b8c3072275811ec775205575bb55190247">ARM and Thumb lifting for <code class="language-plaintext highlighter-rouge">VRHADD</code> and <code class="language-plaintext highlighter-rouge">VRECPE</code></a>, and fixed <code class="language-plaintext highlighter-rouge">SBC</code> immediate handling</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/b72433b42a3dd5dc905f98d891b70552a5d10f2d">FreeBSD PowerPC and RISC-V support</a></li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/dc945aa19fdb6d0ce3f331e9ad241ff0b5dc8bb2"><code class="language-plaintext highlighter-rouge">armv8</code> support to the free version</a></li>
  <li><strong>Feature</strong>: Added a <a href="https://github.com/Vector35/binaryninja-api/commit/c1b0eb7bf58e7234d5930c1c2b4d0987b71c99d1">little-endian <code class="language-plaintext highlighter-rouge">octeon</code> MIPS architecture</a></li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/a08a9ed6be0d2634ae1c36e9774a3fafd542fdb3">architecture callbacks</a> for selecting the initial <a href="https://docs.binary.ninja/dev/concepts.html#permissions-impact-on-linear-sweep">linear sweep</a> alignment</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/a08a9ed6be0d2634ae1c36e9774a3fafd542fdb3">architecture-specific linear sweep capabilities</a></li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/issues/4710">automatic import and application of JNI types</a></li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/aacc5f7f7a806e18d65a24bf6635eadba7063086">big-endian support for the <code class="language-plaintext highlighter-rouge">C-SKY v2</code> architecture</a> and fixed recognition of big-endian <code class="language-plaintext highlighter-rouge">M-CORE</code> binaries</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/206656c8bc3f520c03cbe96e1bc8ca6e0a8f9e24">decoding and lifting support for RISC-V <code class="language-plaintext highlighter-rouge">Zba</code>, <code class="language-plaintext highlighter-rouge">Zbb</code></a>, and <code class="language-plaintext highlighter-rouge">Zbs</code> bitmanip extensions and WCH instructions</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/da3ff7a2e1c05535a9e5f689000c2e5aec957ac6">disassembly and lifting support</a> for Apple’s vendor-specific <code class="language-plaintext highlighter-rouge">aarch64</code> instructions</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/issues/5418">lifting for the ARM <code class="language-plaintext highlighter-rouge">vcvt.f64.s32</code></a> and <code class="language-plaintext highlighter-rouge">vmov.f64</code> instructions</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/f905a0133585fc7385c6e8ef0270bc6e0704cc2a">return value location handling</a> for the <code class="language-plaintext highlighter-rouge">x86</code>/<code class="language-plaintext highlighter-rouge">x86_64</code> ELF ABI</li>
  <li><strong>Feature</strong>: Added support for <a href="https://github.com/Vector35/binaryninja-api/commit/be0e58a664a7e7ba1d74c8853b4c4bb8ff83a041">WCH vendor-specific RISC-V extensions</a>, including a hardware-accelerated memory copy and custom compressed instructions</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/15276775d379c8ca24f6a2f53827e853ecd3f6f2">support for <code class="language-plaintext highlighter-rouge">ARM64_RELOC_BRANCH26</code></a>, <code class="language-plaintext highlighter-rouge">ARM64_RELOC_GOT_LOAD_PAGE21</code>, and <code class="language-plaintext highlighter-rouge">ARM64_RELOC_GOT_LOAD_PAGEOFF12</code> relocations on <code class="language-plaintext highlighter-rouge">aarch64</code></li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/ebd1c774a8d3ed0dd99e961f8191d2924a1c9e6b">support for big-endian <code class="language-plaintext highlighter-rouge">NDS32</code> architecture</a></li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/206656c8bc3f520c03cbe96e1bc8ca6e0a8f9e24">support for the RISC-V <code class="language-plaintext highlighter-rouge">Zbs</code> single-bit bit-manipulation instructions</a></li>
  <li><strong>Feature</strong>: Implemented <a href="https://github.com/Vector35/binaryninja-api/commit/8260b060c118183ce3cb83b78902d92eb64fd279">RISC-V <code class="language-plaintext highlighter-rouge">Zba</code> address-generation instructions</a></li>
  <li><strong>Feature</strong>: Implemented <a href="https://github.com/Vector35/binaryninja-api/commit/eab3411cd4889de07793985022cdeb544c597c96">some <code class="language-plaintext highlighter-rouge">Zbb</code> bit-manipulation instructions for RISC-V</a></li>
  <li><strong>Feature</strong>: Implemented the <a href="https://github.com/Vector35/binaryninja-api/commit/74591a0c6f85ff02144906e2b8eb79edb5c68aac">remaining <code class="language-plaintext highlighter-rouge">Zbb</code> instructions for the <code class="language-plaintext highlighter-rouge">RISC-V</code> architecture</a></li>
  <li><strong>Improvement</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/1a52b290a9934452d222a53b847c678b4ab9255c">ABI-sized heuristic return sizing for <code class="language-plaintext highlighter-rouge">MIPS R5900</code></a></li>
  <li><strong>Improvement</strong>: <a href="https://github.com/Vector35/binaryninja-api/commit/7b1644361d3af01fbedc3468ff0ecf9a801e0948">Coalesced Thumb <code class="language-plaintext highlighter-rouge">IT</code> blocks</a> with trailing conditional branches</li>
  <li><strong>Improvement</strong>: Emitted <a href="https://github.com/Vector35/binaryninja-api/commit/0c42e5b2491d890ae7bda0570ab57470c4a48940"><code class="language-plaintext highlighter-rouge">abs</code> instructions</a> during <a href="https://docs.binary.ninja/dev/archplatform-lifting.html#arithmetic">lifting</a> for the <code class="language-plaintext highlighter-rouge">csky</code> architecture</li>
  <li><strong>Improvement</strong>: Emitted <a href="https://github.com/Vector35/binaryninja-api/commit/0c42e5b2491d890ae7bda0570ab57470c4a48940"><code class="language-plaintext highlighter-rouge">abs</code>, <code class="language-plaintext highlighter-rouge">min</code>, and <code class="language-plaintext highlighter-rouge">max</code> instructions</a> during <code class="language-plaintext highlighter-rouge">aarch64</code> lifting</li>
  <li><strong>Improvement</strong>: Emitted <a href="https://github.com/Vector35/binaryninja-api/commit/0c42e5b2491d890ae7bda0570ab57470c4a48940"><code class="language-plaintext highlighter-rouge">abs</code>, <code class="language-plaintext highlighter-rouge">min</code>, and <code class="language-plaintext highlighter-rouge">max</code> instructions</a> when lifting Hexagon code</li>
  <li><strong>Improvement</strong>: Emitted <a href="https://github.com/Vector35/binaryninja-api/commit/0c42e5b2491d890ae7bda0570ab57470c4a48940"><code class="language-plaintext highlighter-rouge">abs</code>, <code class="language-plaintext highlighter-rouge">min</code>, and <code class="language-plaintext highlighter-rouge">max</code> instructions</a> when lifting <code class="language-plaintext highlighter-rouge">nds32</code> code</li>
  <li><strong>Improvement</strong>: Emitted <a href="https://github.com/Vector35/binaryninja-api/commit/9ad9d390d11ae178629e9a5807bfe14042df0dc5"><code class="language-plaintext highlighter-rouge">bswap</code>, <code class="language-plaintext highlighter-rouge">clz</code>, and <code class="language-plaintext highlighter-rouge">rbit</code> instructions during lifting</a> for <code class="language-plaintext highlighter-rouge">armv7</code></li>
  <li><strong>Improvement</strong>: Emitted <a href="https://github.com/Vector35/binaryninja-api/commit/144cd0aa1f13baebac43d5c877dc7cec8e07b389"><code class="language-plaintext highlighter-rouge">bswap</code>, <code class="language-plaintext highlighter-rouge">popcnt</code>, <code class="language-plaintext highlighter-rouge">clz</code>, <code class="language-plaintext highlighter-rouge">ctz</code>, <code class="language-plaintext highlighter-rouge">cls</code></a>, and <code class="language-plaintext highlighter-rouge">rbit</code> instructions directly during lifting on <code class="language-plaintext highlighter-rouge">aarch64</code> instead of using intrinsics</li>
  <li><strong>Improvement</strong>: Emitted <a href="https://github.com/Vector35/binaryninja-api/commit/cb972a3d4fe468bf1d51af2ce756e99d9e6dbfe4"><code class="language-plaintext highlighter-rouge">bswap</code>, <code class="language-plaintext highlighter-rouge">popcnt</code>, <code class="language-plaintext highlighter-rouge">clz</code>, and <code class="language-plaintext highlighter-rouge">ctz</code> instructions</a> during x86 lifting</li>
  <li><strong>Improvement</strong>: <a href="https://github.com/Vector35/binaryninja-api/commit/f5ebdefdf0580eb38d8a2ea546fd78657eb26a7f">Expanded ARM, <code class="language-plaintext highlighter-rouge">Thumb</code>, and <code class="language-plaintext highlighter-rouge">NEON</code> lifting coverage</a> for the ARMv7 architecture</li>
  <li><strong>Improvement</strong>: Improved <a href="https://github.com/Vector35/binaryninja-api/commit/6bc36d9f834900d8b9b15ecc6956aaa3d39bf153"><code class="language-plaintext highlighter-rouge">MIPS n32</code> ABI support</a></li>
  <li><strong>Improvement</strong>: Improved <a href="https://github.com/Vector35/binaryninja-api/commit/dedcfe267357761885bb167b03b200a92a04dcce"><code class="language-plaintext highlighter-rouge">defaultarch</code> inlining to detect registers set</a> to the caller’s return address and treat jumps to them in the callee IL as returns</li>
  <li><strong>Improvement</strong>: Improved <a href="https://github.com/Vector35/binaryninja-api/commit/1a52b290a9934452d222a53b847c678b4ab9255c">heuristic return sizing to use ABI-based sizes</a> for <code class="language-plaintext highlighter-rouge">MIPS R5900</code></li>
  <li><strong>Improvement</strong>: Improved <a href="https://github.com/Vector35/binaryninja-api/commit/8ed744a615909ac4bec2bc6dd92cf5cb0485cf07">library tracking for imported symbols in Mach-O binaries</a></li>
  <li><strong>Improvement</strong>: Improved <a href="https://github.com/Vector35/binaryninja-api/commit/c1b0eb7bf58e7234d5930c1c2b4d0987b71c99d1">support for the <code class="language-plaintext highlighter-rouge">octeon</code> and <code class="language-plaintext highlighter-rouge">n32</code> MIPS ABIs</a></li>
  <li><strong>Improvement</strong>: Improved <a href="https://github.com/Vector35/binaryninja-api/commit/a09ee8d47d6bb923a8ad6eccea9980dcf8bc35fe">x86 LLIL flag lifting for arithmetic, test, rotate</a>, and shift instructions</li>
  <li><strong>Improvement</strong>: <a href="https://github.com/Vector35/binaryninja-api/commit/0c42e5b2491d890ae7bda0570ab57470c4a48940">Lifted <code class="language-plaintext highlighter-rouge">abs</code>, <code class="language-plaintext highlighter-rouge">min</code>, and <code class="language-plaintext highlighter-rouge">max</code> instructions</a> for the <code class="language-plaintext highlighter-rouge">tricore</code> architecture</li>
  <li><strong>Improvement</strong>: Lifted more <code class="language-plaintext highlighter-rouge">TriCore</code> instructions added in the 1.8 architecture revision</li>
  <li><strong>Improvement</strong>: Preserved <a href="https://github.com/Vector35/binaryninja-api/commit/e994e4131b58dc3cd7210f8c45e8c2054b79a872">native symbols</a> when generating <a href="https://docs.binary.ninja/guide/types/debuginfo.html#special-note-for-dsym-files">macOS dSYMs</a></li>
  <li><strong>Improvement</strong>: <a href="https://github.com/Vector35/binaryninja-api/commit/cbfc477e880df1deb6bf8ee062b0f9eb0d26ab4d">Recovered implicit <code class="language-plaintext highlighter-rouge">this</code> parameters</a> in <code class="language-plaintext highlighter-rouge">GNU3</code>-mangled symbols</li>
  <li><strong>Improvement</strong>: Updated <a href="https://github.com/Vector35/binaryninja-api/commit/8507ff7444b574437bb02162cf63d957fb4502a0">RISC-V <code class="language-plaintext highlighter-rouge">Zbb</code> bitmanip lifting</a> to use first-class LLIL operations for <code class="language-plaintext highlighter-rouge">min</code>/<code class="language-plaintext highlighter-rouge">max</code>, <code class="language-plaintext highlighter-rouge">clz</code>/<code class="language-plaintext highlighter-rouge">ctz</code>, and <code class="language-plaintext highlighter-rouge">popcount</code></li>
  <li><strong>Improvement</strong>: Updated <a href="https://github.com/Vector35/binaryninja-api/commit/9ad9d390d11ae178629e9a5807bfe14042df0dc5"><code class="language-plaintext highlighter-rouge">aarch64</code>, <code class="language-plaintext highlighter-rouge">armv7</code> and <code class="language-plaintext highlighter-rouge">x86</code> lifting</a> to emit new bitwise operation IL instructions</li>
  <li><strong>Improvement</strong>: Used a 64KiB default page size on <code class="language-plaintext highlighter-rouge">AArch64</code> Linux</li>
  <li><strong>Fix</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/20b99b72d2bda9504d12f11d24bc07f95b41d048">special handling for <code class="language-plaintext highlighter-rouge">0000</code> in RISC-V disassembly</a> to work around a binary parsing issue</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/25782a765de38c1634f7eccdfc51fe12a2e570a5">ARMv7 <code class="language-plaintext highlighter-rouge">vcvt</code> lifting and added support</a> for lifting scalar <code class="language-plaintext highlighter-rouge">vabs</code> directly when lane and register widths match</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/4430">Thumb2 <code class="language-plaintext highlighter-rouge">IT</code> conditional block analysis</a> so subsequent instructions like <a href="https://api.binary.ninja/cpp/group__core.html#a39a71aa45c3ae68705811e1c0a0215fb"><code class="language-plaintext highlighter-rouge">b</code></a> are correctly recognized as conditional</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/3992">ARMv7 <code class="language-plaintext highlighter-rouge">rev</code> instruction lifting</a> that lost the initial most-significant byte</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/f1a688a1e7fb6d962d8c9addaaefdfd59e5dd28b">DWARF import</a> using the wrong address width for unknown architectures</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/8102">Thumb-2 ELF functions referenced from <code class="language-plaintext highlighter-rouge">.gnu_debugdata</code></a> being created as ARM functions instead of Thumb-2</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/0f83383002556847ac5eb0908592324c8b64646f">WCH RISC-V architecture registration and ELF relocation lookup</a> by renaming it to <code class="language-plaintext highlighter-rouge">rv32gc_wch</code> to match the existing RISC-V architecture</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/64f0668dedd528790837393dc8d59bf5da458478"><code class="language-plaintext highlighter-rouge">IT</code> instruction info</a> in the Thumb2 architecture</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/905bf923da016b2c3941b03daa9c9cb3b8b07f81">full-width bit field instruction lifting</a> for <code class="language-plaintext highlighter-rouge">BFI</code> and <code class="language-plaintext highlighter-rouge">BFC</code> on ARMv7</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/8198">incorrect lifting of x86 <code class="language-plaintext highlighter-rouge">ANDN</code>/<code class="language-plaintext highlighter-rouge">PANDN</code>/<code class="language-plaintext highlighter-rouge">VPANDN</code></a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/fa09f36b5f47ed690dc029fe9f1ed9ad4ebce7c8">incorrect lifting</a> of double precision <code class="language-plaintext highlighter-rouge">FMOV</code> immediate on <code class="language-plaintext highlighter-rouge">aarch64</code></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/26fa100ed19ab0b497f9be16c12f6adec6716e3f">stack adjustment for <code class="language-plaintext highlighter-rouge">pop r16</code> on x86</a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/4030">x86 <code class="language-plaintext highlighter-rouge">MOVSS</code> lifting</a> to zero-extend the memory-source form</li>
  <li><strong>Fix</strong>: Fixed <code class="language-plaintext highlighter-rouge">LHA</code> instruction encoding on <code class="language-plaintext highlighter-rouge">TriCore</code></li>
  <li><strong>Fix</strong>: Fixed <code class="language-plaintext highlighter-rouge">lwpc</code> and <code class="language-plaintext highlighter-rouge">restore.jrc</code> lifting for nanoMIPS</li>
  <li><strong>Fix</strong>: Fixed a <a href="https://api.binary.ninja/cpp/group__binaryview.html#class_binary_ninja_1_1_binary_view"><code class="language-plaintext highlighter-rouge">BinaryView</code></a> leak in <code class="language-plaintext highlighter-rouge">VxWorksViewType::IsValidForData</code></li>
  <li><strong>Fix</strong>: Fixed a <a href="https://github.com/Vector35/binaryninja-api/issues/1546">demangling error</a> for MSVC-mangled <code class="language-plaintext highlighter-rouge">operator+</code> overloads on <code class="language-plaintext highlighter-rouge">basic_string</code></li>
  <li><strong>Fix</strong>: Fixed a <a href="https://github.com/Vector35/binaryninja-api/commit/6acb6ece0e3cc13e86afe4e48ec71e4e2ff6875b">bounds-checking issue in the Mach-O parser</a> to improve robustness</li>
  <li><strong>Fix</strong>: Fixed a <a href="https://github.com/Vector35/binaryninja-api/commit/0987f679b31655bcdf3254d2906d36fd9d393aee">crash from a malformed PE exception directory table size</a></li>
  <li><strong>Fix</strong>: Fixed a crash when looking up token hover values for architecture-less items</li>
  <li><strong>Fix</strong>: Fixed a <a href="https://github.com/Vector35/binaryninja-api/commit/e616cdea07bcee961d9c2e4b4720836d55d094c5">crash when reading a malformed <code class="language-plaintext highlighter-rouge">CFString</code> in Mach-O binaries</a></li>
  <li><strong>Fix</strong>: Fixed a <a href="https://github.com/Vector35/binaryninja-api/commit/b24fcc83e829e3f367b88b507daf23e57bce66c2">hang during MIPS ELF symbol lookup caused</a> by a malformed symbol table with a <code class="language-plaintext highlighter-rouge">GOT</code> entry outside valid memory regions</li>
  <li><strong>Fix</strong>: Fixed a missing <code class="language-plaintext highlighter-rouge">CALLI</code> variant in the <code class="language-plaintext highlighter-rouge">TriCore</code> architecture added in 1.8</li>
  <li><strong>Fix</strong>: Fixed a <a href="https://github.com/Vector35/binaryninja-api/commit/96d00358954807095418da56421467f2f93dd905">race condition</a> in <code class="language-plaintext highlighter-rouge">x64</code> platform view initialization on Windows</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/d7af6fdf063b85c6bfc58182d1665f906987ecbf">adding the image base</a> when looking up section-relative symbols in ELF files</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/7880">alternate names in the <code class="language-plaintext highlighter-rouge">PPC32</code> and <code class="language-plaintext highlighter-rouge">thumb2</code> type libraries</a> and added an API to remove <a href="https://docs.binary.ninja/dev/archplatform-platform.html#alternate-names">alternate names</a></li>
  <li><strong>Fix</strong>: Fixed an <a href="https://github.com/Vector35/binaryninja-api/commit/06611c17ae5ee5936889ff029cac042fdba8a0c5">out-of-bounds read during Thumb-2 lifting</a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/7905">analysis giving up on <code class="language-plaintext highlighter-rouge">Hexagon</code> functions</a> with <code class="language-plaintext highlighter-rouge">Exceeds 'analysis.limits.maxFunctionUpdateCount'</code> errors</li>
  <li><strong>Fix</strong>: Fixed correctness issues in the <code class="language-plaintext highlighter-rouge">GNU3</code> demangler</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/20b99b72d2bda9504d12f11d24bc07f95b41d048">disassembly of RISC-V <code class="language-plaintext highlighter-rouge">0000</code> trap instructions</a> that some compilers insert after jumps</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/544b7ee320dd8dd69f7b368a36ee72e3faf7e640">handling of <code class="language-plaintext highlighter-rouge">ARM64_RELOC_GOT_LOAD_PAGEOFF12</code></a> and <code class="language-plaintext highlighter-rouge">ARM64_RELOC_GOT_LOAD_PAGE21</code> relocations for <code class="language-plaintext highlighter-rouge">aarch64</code></li>
  <li><strong>Fix</strong>: Fixed handling of non-monotonic records in <code class="language-plaintext highlighter-rouge">Intel Hex</code> files</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/5962">inability to override architecture selection</a> for Thumb2 ELF files with an even entry point address</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/64f0668dedd528790837393dc8d59bf5da458478">incorrect instruction info for Thumb2 <code class="language-plaintext highlighter-rouge">IT</code> instructions</a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/371fe215911a9a73f57cfe018e38924a836b6b7b">incorrect ordering when popping values from a register stack</a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/9e37452fed25ab7ef66a8e8f8206b3227911c611">inline return detection</a> to avoid treating <code class="language-plaintext highlighter-rouge">LLIL_JUMP(reg)</code> as an inline return when the callee uses a nonstandard return register</li>
  <li><strong>Fix</strong>: Fixed lift for <a href="https://api.binary.ninja/binaryninja.lowlevelil-module.html#binaryninja.lowlevelil.LowLevelILFunction.pop"><code class="language-plaintext highlighter-rouge">pop</code></a> with segment registers on x86</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/f978f397fd06978e8eda7776e0fa9c9bfd30d2d9">lift of <code class="language-plaintext highlighter-rouge">JAL</code> on RISC-V</a> by properly setting the return register</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/585943aeb18115f36c1222211584e2ab08785824">lifting for <code class="language-plaintext highlighter-rouge">MOVSS</code> and <code class="language-plaintext highlighter-rouge">ANDN</code> on x86</a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/3988">lifting of <code class="language-plaintext highlighter-rouge">sbc.s</code> on <code class="language-plaintext highlighter-rouge">ARMv7</code></a> so the overflow flag is computed instead of left <code class="language-plaintext highlighter-rouge">unimplemented</code></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/905bf923da016b2c3941b03daa9c9cb3b8b07f81">lifting of full-width bit field instructions on <code class="language-plaintext highlighter-rouge">ARMv7</code></a></li>
  <li><strong>Fix</strong>: Fixed out-of-order <code class="language-plaintext highlighter-rouge">TriCore</code> disassembly operands for instructions added in 1.8</li>
  <li><strong>Fix</strong>: Fixed the GNU3 demangler to use its registered config path</li>
  <li><strong>Fix</strong>: Fixed the <a href="https://github.com/Vector35/binaryninja-api/issues/8290">RISC-V architecture not disassembling the <code class="language-plaintext highlighter-rouge">sh2add</code> instruction</a></li>
  <li><strong>Fix</strong>: Fixed the <a href="https://github.com/Vector35/binaryninja-api/commit/4bba210293dc020fbd8ef84f9f1b91676a4c7432">PE loader</a> creating symbols for debugging metadata symbol entries</li>
  <li><strong>Fix</strong>: Fixed the <code class="language-plaintext highlighter-rouge">ARM</code>/<code class="language-plaintext highlighter-rouge">Thumb2</code> function platform for <code class="language-plaintext highlighter-rouge">.gnu_debugdata</code> symbols</li>
  <li><strong>Fix</strong>: Fixed the <a href="https://github.com/Vector35/binaryninja-api/issues/3990">carry flag not being lifted</a> for the <code class="language-plaintext highlighter-rouge">ARMv7</code> <code class="language-plaintext highlighter-rouge">lsl.s</code> instruction</li>
  <li><strong>Fix</strong>: Fixed the <a href="https://github.com/Vector35/binaryninja-api/commit/17e0ed9cdf8970ce54b6d2f5c6c533bba2e63ae2">rounding flag not being properly emitted on some <code class="language-plaintext highlighter-rouge">x86</code> floating point instructions</a></li>
  <li><strong>Fix</strong>: Fixed type lookup for Thumb function pointers by normalizing the address before lookup</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/6075">unimplemented ARMv7/Thumb2 lifting</a> for several multiply/divide, sync primitive, and SIMD/FP instructions including <code class="language-plaintext highlighter-rouge">vld1</code>, <code class="language-plaintext highlighter-rouge">vst1</code>, <code class="language-plaintext highlighter-rouge">vldmia</code>, <code class="language-plaintext highlighter-rouge">vstmia</code>, <code class="language-plaintext highlighter-rouge">umaal</code>, and <code class="language-plaintext highlighter-rouge">clrex</code></li>
  <li><strong>Fix</strong>: Hardened <a href="https://github.com/Vector35/binaryninja-api/commit/6acb6ece0e3cc13e86afe4e48ec71e4e2ff6875b">Mach-O parsing</a> against out-of-bounds reads by tightening bounds checks and bounding rebase/bind entry limits</li>
  <li><strong>Fix</strong>: Ignored <a href="https://github.com/Vector35/binaryninja-api/commit/1463cbe50209ac9a43c67be6d586b23f17ab08f5"><code class="language-plaintext highlighter-rouge">R_RISCV_RELAX</code></a> relocations on RISC-V</li>
  <li><strong>Fix</strong>: Implemented <a href="https://github.com/Vector35/binaryninja-api/issues/4044"><code class="language-plaintext highlighter-rouge">C</code>, <code class="language-plaintext highlighter-rouge">P</code>, <code class="language-plaintext highlighter-rouge">A</code>, and <code class="language-plaintext highlighter-rouge">O</code> flags for <code class="language-plaintext highlighter-rouge">sbb.d</code>, <code class="language-plaintext highlighter-rouge">lsr.d</code>, <code class="language-plaintext highlighter-rouge">and.b</code></a>, and <code class="language-plaintext highlighter-rouge">xor.d</code> instructions</li>
  <li><strong>Fix</strong>: Marked <code class="language-plaintext highlighter-rouge">_exit</code> as non-returning for iOS Thumb</li>
  <li><strong>Fix</strong>: Marked <code class="language-plaintext highlighter-rouge">abort</code> and other <code class="language-plaintext highlighter-rouge">noreturn</code> functions as <a href="https://docs.binary.ninja/guide/types/attributes.html#functions-that-dont-return"><code class="language-plaintext highlighter-rouge">__noreturn</code></a> on Apple platforms to prevent them from appearing to fall through</li>
  <li><strong>Fix</strong>: Fixed the <a href="https://github.com/Vector35/binaryninja-api/commit/c0e0b93f5305fd7746f8188df5c3943be2d061be">default calling convention for MSP430</a>, which was backwards</li>
</ul>

<h2 id="core-plugins">Core Plugins</h2>

<ul>
  <li><strong>Feature</strong>: Added a <a href="https://github.com/Vector35/binaryninja-api/commit/bcd30a28c94442f088cb20800e5c7e10fc344f48">strings table</a> to the <a href="https://docs.binary.ninja/guide/sharedcache.html#shared-cache-triage-dsctriage">shared cache triage view</a>, showing strings from every image in the shared cache</li>
  <li><strong>Feature</strong>: Added a <a href="https://docs.binary.ninja/guide/kernelcache.html"><code class="language-plaintext highlighter-rouge">KernelCache</code></a> workflow activity to rename stubs in <code class="language-plaintext highlighter-rouge">__auth_stubs</code> sections based on their target symbol name</li>
  <li><strong>Feature</strong>: Added a <a href="https://github.com/Vector35/binaryninja-api/commit/fe59f77889bcaa8c9cec219d9c95f8d89b1b12f4">recursive load button to the Dyld Shared Cache triage view</a></li>
  <li><strong>Feature</strong>: Added an <a href="https://github.com/Vector35/binaryninja-api/commit/639e9298ca990942753ee2fea29c7a71e8766af3">activity to rename <code class="language-plaintext highlighter-rouge">objc_msgSend</code> stub functions, helping</a> with stripped binaries such as macOS 27</li>
  <li><strong>Improvement</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/9a3859fe00c4df38c2d860ef33184531964cc269">Objective-C support</a> for method type strings using pointers relative to the selector base address, as seen in iOS 27 shared caches</li>
  <li><strong>Improvement</strong>: Added back the <a href="https://docs.binary.ninja/guide/binexport.html"><code class="language-plaintext highlighter-rouge">BinExport</code></a> command to all paid product versions</li>
  <li><strong>Improvement</strong>: Improved UX when <a href="https://docs.binary.ninja/guide/sharedcache.html#opening-a-shared-cache">loading the shared cache</a></li>
  <li><strong>Improvement</strong>: Improved <a href="https://github.com/Vector35/binaryninja-api/issues/6630">handling of shared cache files in projects</a></li>
  <li><strong>Improvement</strong>: Reduced <a href="https://github.com/Vector35/binaryninja-api/commit/5bf826bb8826c9113cf958f08892e5be1fcc2960">log noise when loading iOS/macOS 27 shared caches</a></li>
  <li><strong>Improvement</strong>: Refactored the <a href="https://github.com/Vector35/binaryninja-api/commit/216f77e473fe5bafdf576f137ce76dc8309e11a8">DSC symbols table to use <code class="language-plaintext highlighter-rouge">TriageTablePanel</code></a>, adding asynchronous loading, filtering, and sorting</li>
  <li><strong>Improvement</strong>: <a href="https://github.com/Vector35/binaryninja-api/commit/4a33800c81e540b6a641a624c4739d3abdc51329">Resolved cross-image stub functions to their target image</a> in <code class="language-plaintext highlighter-rouge">KernelCache</code> context menu actions</li>
  <li><strong>Improvement</strong>: Set <a href="https://github.com/Vector35/binaryninja-api/commit/e2bcf29ae986371148d67c608b7d74dcb9b608af">region display names</a> for the <code class="language-plaintext highlighter-rouge">KernelCache</code> to make it easier to obtain segment bounds</li>
  <li><strong>Improvement</strong>: <a href="https://github.com/Vector35/binaryninja-api/commit/0dd311b8277d2c17aa62f9f6762b992cbf7628bb">Stored processed Objective-C metadata</a> in the database instead of regenerating it on load</li>
  <li><strong>Improvement</strong>: The <a href="https://github.com/Vector35/binaryninja-api/commit/aa8dab21d44b4e0dd863f0867c7e735cfb878a4d">triage view</a> is now always shown when opening a shared cache or kernel cache</li>
  <li><strong>Improvement</strong>: <a href="https://github.com/Vector35/binexport/commit/14cb476e4b9f334e3c5f292303e8f45f8858949b">Used the demangler API for exported function names</a> in the <code class="language-plaintext highlighter-rouge">binexport</code> plugin</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/0d6a15ce324c04d25b62a5914309d83d2122111d">IDB import not being freed</a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/8184">headless loading of a <code class="language-plaintext highlighter-rouge">bndb</code> extracted from a container</a> being parsed as <code class="language-plaintext highlighter-rouge">Raw</code>/<code class="language-plaintext highlighter-rouge">Mapped</code> instead of restoring the analyzed database</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/912465b5cf1d0442443d9584e15111361f27751c">miscellaneous crashes</a> in the Objective-C plugin when analyzing malformed binaries</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/cbab54c24a34c3939f9607cd066b460d79a6965b"><code class="language-plaintext highlighter-rouge">Load /usr/lib/libFoo.dylib</code> context menu action</a> in the Dyld Shared Cache view to resolve cross-image stub functions to their target image</li>
  <li><strong>Fix</strong>: Fixed <code class="language-plaintext highlighter-rouge">objc_msgSend$stub</code> functions incorrectly appearing in <code class="language-plaintext highlighter-rouge">__objc_stubs</code> on iOS/macOS 27 shared caches</li>
  <li><strong>Fix</strong>: Fixed a <a href="https://github.com/Vector35/binaryninja-api/commit/c33abcaac6cdb0f9088d251705e49d855b593a5e">potential object lifetime issue</a> in DSC (Dyld Shared Cache) support</li>
  <li><strong>Fix</strong>: Fixed insufficient bounds checking on <code class="language-plaintext highlighter-rouge">UTF8</code> CFStrings in the <a href="https://github.com/Vector35/binaryninja-api/commit/5fe1980a95f956c1f58974de27fbbfbfac1258af">Objective-C</a> analyzer</li>
  <li><strong>Fix</strong>: Fixed missing parameter types on <a href="https://docs.binary.ninja/guide/objectivec.html">Objective-C</a> methods in shared caches</li>
  <li><strong>Fix</strong>: Fixed potential crashes from using invalid plugin objects</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/991d6f11d375898aea3bd2227aa5abe43e78be0a">resolution of calls via <code class="language-plaintext highlighter-rouge">__auth_stubs</code> in the kernel cache</a> for iOS 27 / macOS 27</li>
  <li><strong>Fix</strong>: Fixed the <a href="https://github.com/Vector35/binaryninja-api/issues/7315">Objective-C workflow overriding user-specified call types</a> for <code class="language-plaintext highlighter-rouge">objc_msgSend</code> calls, preventing users from refining inferred types to account for variadic arguments</li>
  <li><strong>Fix</strong>: Fixed the <a href="https://github.com/Vector35/binaryninja-api/issues/8083">DSC triage view</a> not being displayed by default when reopening a dyld shared cache from disk</li>
  <li><strong>Fix</strong>: Fixed the type library utility plugin not loading</li>
</ul>

<h2 id="extension-manager-1">Extension Manager</h2>

<ul>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/4748">Extension Manager hanging</a> until a request timed out when closing it while an unreachable <a href="https://docs.binary.ninja/dev/plugins.html#using-your-own-plugin-repository">third-party repository</a> was configured</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/8092">installed plugins missing their descriptions</a> in the Extension Manager</li>
  <li><strong>Fix</strong>: Fixed a <a href="https://github.com/Vector35/binaryninja-api/commit/f2ae12d97604da6136b26c184eb7fe30531b4d5e"><code class="language-plaintext highlighter-rouge">null</code> pointer crash</a> in the <a href="https://docs.binary.ninja/guide/plugins.html#installing-via-the-api">plugin install API</a></li>
  <li><strong>Fix</strong>: Fixed a crash when a plugin repository returned a non-JSON response</li>
  <li><strong>Fix</strong>: Fixed a null pointer dereference when the plugin repository is missing</li>
  <li><strong>Fix</strong>: Fixed handling of empty unofficial repository URLs in the Extension Manager</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/6a06d6730eaae9339507c0639215f92940085cfb">handling of installed extensions</a> that have since been removed</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/8095">handling of plugins with no dependencies</a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/8093">installed plugin titles</a> in the Extension Manager not being clickable links to their repositories</li>
  <li><strong>Fix</strong>: Fixed license text rendering as plaintext in the Extension Manager</li>
  <li><strong>Fix</strong>: Fixed lock ordering issues in the Extension Manager</li>
  <li><strong>Fix</strong>: Fixed memory leaks in the Extension Manager</li>
  <li><strong>Fix</strong>: Fixed migration to also reinstall legacy plugin dependencies</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/8122">native wheel installation failures caused</a> by pip not inheriting the system <code class="language-plaintext highlighter-rouge">PATH</code> when resolving native dependencies like <code class="language-plaintext highlighter-rouge">clang</code></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/8121">pip installation errors not being shown in the UI</a> when plugin dependencies fail to install</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/2889">plugin actions not being available immediately</a> after loading a plugin</li>
  <li><strong>Fix</strong>: Fixed plugins without dependency providers failing to load</li>
  <li><strong>Fix</strong>: Fixed repository booleans not actually disabling repositories</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/412c943f5813960f7762a526a3c2df06768a721b">several situations</a> where the Extension Manager did not select the latest plugin version</li>
  <li><strong>Fix</strong>: Fixed the Extension Manager to properly override old repo URLs when new ones are added</li>
  <li><strong>Fix</strong>: Fixed the Extension Manager crashing Python when <code class="language-plaintext highlighter-rouge">plugin_status.json</code> is invalid</li>
  <li><strong>Fix</strong>: Fixed the <a href="https://github.com/Vector35/binaryninja-api/commit/f2ae12d97604da6136b26c184eb7fe30531b4d5e">Python <code class="language-plaintext highlighter-rouge">plugin install</code> API to default to the latest version</a></li>
  <li><strong>Fix</strong>: Fixed the <a href="https://github.com/Vector35/binaryninja-api/issues/8109">UI hanging when disabling or uninstalling a plugin</a> while the Extension Manager is updating</li>
  <li><strong>Fix</strong>: Fixed the <a href="https://github.com/Vector35/binaryninja-api/issues/8123">UI hanging when installing a Python module</a> from the Extension Manager</li>
  <li><strong>Fix</strong>: Fixed the <a href="https://github.com/Vector35/binaryninja-api/issues/8392">dependency install dialog</a> repeatedly prompting to install dependencies that were already installed</li>
  <li><strong>Fix</strong>: Fixed the <a href="https://github.com/Vector35/binaryninja-api/issues/8371">plugin dependency dialog</a> not resolving <code class="language-plaintext highlighter-rouge">\n</code> newlines in its JSON output</li>
  <li><strong>Fix</strong>: Fixed the <a href="https://github.com/Vector35/binaryninja-api/issues/7572">Extension Manager</a> writing a failed download’s error response to disk as a zip instead of failing early on a non-200 status code</li>
  <li><strong>Fix</strong>: Fixed the <a href="https://github.com/Vector35/binaryninja-api/issues/8094">Extension Manager</a> prompting to force-install plugins even when the installed version satisfies requirements</li>
  <li><strong>Fix</strong>: Fixed the <code class="language-plaintext highlighter-rouge">Install Python Dependency</code> action hanging the UI by running <code class="language-plaintext highlighter-rouge">pip</code> installation as a background task</li>
  <li><strong>Fix</strong>: Fixed the <a href="https://github.com/Vector35/binaryninja-api/issues/8311">deferred uninstall state not resetting</a> after a plugin was reinstalled</li>
  <li><strong>Fix</strong>: Fixed the Extension Manager using the wrong target directory when updating plugins</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/8266">version sorting in the Extension Manager</a></li>
</ul>

<h2 id="collaboration--projects">Collaboration / Projects</h2>

<ul>
  <li><strong>Feature</strong>: Added an <a href="https://api.binary.ninja/cpp/namespace_binary_ninja_1_1_enterprise.html#a4d00e6c37583d337a4a255fdda7fef11"><code class="language-plaintext highlighter-rouge">AuthenticateWithToken</code></a> API for Enterprise to authenticate directly with a token</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/issues/6927">configurable columns to the <code class="language-plaintext highlighter-rouge">Project Browser</code>, similar</a> to macOS Finder or Windows Explorer</li>
  <li><strong>Improvement</strong>: Changed the <a href="https://github.com/Vector35/binaryninja-api/commit/4963e1da2c001b0eac147482884b9630f9963654">Enterprise Server version</a> to a structured <a href="https://api.binary.ninja/cpp/group__coreapi.html#struct_binary_ninja_1_1_version_info"><code class="language-plaintext highlighter-rouge">VersionInfo</code></a> type instead of a plain string</li>
  <li><strong>Fix</strong>: Fixed <a href="https://docs.binary.ninja/guide/enterprise/index.html">Enterprise</a> snapshot mapping lookups on push when connected</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/5041">project names not resolving on the New Tab page</a> after the project’s first open</li>
  <li><strong>Fix</strong>: Fixed a crash in <a href="https://docs.binary.ninja/guide/enterprise/index.html#chat">collaboration chat</a> during window teardown</li>
  <li><strong>Fix</strong>: Fixed crash when the collaboration user list was empty</li>
  <li><strong>Fix</strong>: Fixed navigation to an already-open tab instead of the requested <a href="https://github.com/Vector35/binaryninja-api/issues/8176">container entry when opening multiple entries from the same container in a project</a></li>
  <li><strong>Fix</strong>: Fixed the <a href="https://github.com/Vector35/binaryninja-api/issues/8076">project table view</a> to accept file and folder drop events instead of trying to open them</li>
  <li><strong>Fix</strong>: Fixed the <a href="https://github.com/Vector35/binaryninja-api/issues/4990">open tab’s name</a> and project browser display name not updating live when a project file was renamed</li>
  <li><strong>Fix</strong>: Prevented downloading a <code class="language-plaintext highlighter-rouge">.bndb</code> before an initial snapshot has been pushed</li>
</ul>

<h2 id="api">API</h2>

<ul>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/d99d2e5f992559d19372177a5c5ebbf477bf84a3">API for deprecated plugins</a></li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/907b4e5b5dad8e4f976e3b59e779686b02390c8f">API to reload the database connection</a></li>
  <li><strong>Feature</strong>: Added APIs for measuring <a href="https://docs.binary.ninja/dev/concepts.html#unicode-support">Unicode</a> string width in character cells and breaking strings into grapheme clusters, and constrained derived strings to the enabled Unicode blocks</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/78af18411c0adc7f79b272d681954896fad68e22">Python constructors for fragment types</a></li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/eaacd6d26ee5ec55aa16080b6afe7947c2629e9c">Binary Similarity APIs</a></li>
  <li><strong>Feature</strong>: Added <a href="https://api.binary.ninja/cpp/group__core.html#gaa1c1912e7c1c5c9221b57ad51637aaad"><code class="language-plaintext highlighter-rouge">BNSimplifyDemangledTemplateName</code></a> API</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/e0e3a306330e1f9cc71d770c89e1b655c03bb516">new license APIs</a></li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/bfd306437f34ebc4d4170c5fb8170261585f6038">recognize_constant_data</a> to the <a href="https://api.binary.ninja/cpp/class_binary_ninja_1_1_string_recognizer.html"><code class="language-plaintext highlighter-rouge">StringRecognizer</code></a> API</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/issues/7512">type slices</a>, a primitive type representing a byte range within a child type without being a pointer</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/7a4c3a3ba86f7523cf24bb964554ec2ff9ea8a05"><code class="language-plaintext highlighter-rouge">Unknown()</code> and <code class="language-plaintext highlighter-rouge">IsUnknown()</code> builder functions</a> to Unimplemented IL across <code class="language-plaintext highlighter-rouge">LLIL</code>/<code class="language-plaintext highlighter-rouge">MLIL</code>/<code class="language-plaintext highlighter-rouge">HLIL</code></li>
  <li><strong>Feature</strong>: Added an API to query <a href="https://api.binary.ninja/cpp/group__action.html#struct_u_i_action"><code class="language-plaintext highlighter-rouge">UIAction</code></a> aliases</li>
  <li><strong>Feature</strong>: Added an <a href="https://github.com/Vector35/binaryninja-api/commit/274197bbc9790909b5a6a6e1a39e19083359ad17">API to specify the file to reopen for moved databases</a></li>
  <li><strong>Feature</strong>: Added an <a href="https://github.com/Vector35/binaryninja-api/commit/0ba0b9e036ba692c053307f4a894bcf0d3534494">API call to remove alternate names</a> from a loaded type library</li>
  <li><strong>Feature</strong>: Added support for <code class="language-plaintext highlighter-rouge">__typeof__</code> and <code class="language-plaintext highlighter-rouge">decltype</code> to the Clang type parser</li>
  <li><strong>Feature</strong>: Added support for populating alias fields into <a href="https://api.binary.ninja/cpp/group__commandpalette.html#a9001b65ddbcaa055391fc5c65c7528c2"><code class="language-plaintext highlighter-rouge">extraSearchableText</code></a> for UI actions, allowing plugins to namespace their command-palette entries</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/e3abb2e90e762bdfa96fe31d6d7a8b839ad85a8a">support for specifying <code class="language-plaintext highlighter-rouge">clang</code> compiler flags</a> when <a href="https://docs.binary.ninja/dev/typelibraries.html#creating">creating BNTLs</a></li>
  <li><strong>Feature</strong>: Added the <a href="https://github.com/Vector35/binaryninja-api/commit/1699a201a555c77ce4d7a29565eede638714dfee"><code class="language-plaintext highlighter-rouge">OnTokenDoubleClicked</code> notification hook</a> to <a href="https://api.binary.ninja/cpp/group__uicontext.html#class_u_i_context_notification"><code class="language-plaintext highlighter-rouge">UIContextNotification</code></a></li>
  <li><strong>Feature</strong>: Exposed <a href="https://github.com/Vector35/binaryninja-api/commit/60133f3eb71b2361dd5edfb407e5fb9bcfe5c71d">flow graph construction</a> to the API</li>
  <li><strong>Feature</strong>: Exposed an <a href="https://github.com/Vector35/binaryninja-api/commit/3003bfaf403bff988d99047959fc9b2aa8602adf">API for running string detection</a> on arbitrary buffers, enabling detection over an entire shared cache</li>
  <li><strong>Feature</strong>: Introduced config-based demangler APIs (<a href="https://api.binary.ninja/cpp/group__core.html#struct_b_n_demangler_config"><code class="language-plaintext highlighter-rouge">BNDemanglerConfig</code></a> and <a href="https://api.binary.ninja/cpp/group__core.html#struct_b_n_demangler_result"><code class="language-plaintext highlighter-rouge">BNDemanglerResult</code></a>) with unified <code class="language-plaintext highlighter-rouge">demangle</code> and template-simplification functions, replacing the legacy demangler entry points</li>
  <li><strong>Feature</strong>: <a href="https://github.com/Vector35/binaryninja-api/commit/73976e975ddf4dd0cbb5aa49425cf36e5655cd5c">Re-added the <code class="language-plaintext highlighter-rouge">License</code> tab and license text field to the API</a></li>
  <li><strong>Improvement</strong>: Added a <a href="https://api.binary.ninja/cpp/group__binaryview.html#class_binary_ninja_1_1_binary_view"><code class="language-plaintext highlighter-rouge">BinaryView</code></a> field to <a href="https://api.binary.ninja/cpp/group__lineardisassembly.html#struct_binary_ninja_1_1_linear_disassembly_line"><code class="language-plaintext highlighter-rouge">LinearDisassemblyLine</code></a></li>
  <li><strong>Improvement</strong>: Added a <a href="https://github.com/Vector35/binaryninja-api/commit/f49bc8fd49477549ea4b36992f62b968921aa217"><code class="language-plaintext highlighter-rouge">reason</code> field</a> to <a href="https://api.binary.ninja/binaryninja.enums-module.html#binaryninja.enums.MediumLevelILOperation.MLIL_FORCE_VER"><code class="language-plaintext highlighter-rouge">MLIL_FORCE_VER</code></a> for use in automated variable splitting</li>
  <li><strong>Improvement</strong>: Added comparison operators to <a href="https://api.binary.ninja/cpp/group__coreapi.html#struct_binary_ninja_1_1_version_info"><code class="language-plaintext highlighter-rouge">VersionInfo</code></a></li>
  <li><strong>Improvement</strong>: Added helper methods to <code class="language-plaintext highlighter-rouge">DominatorTree</code> for walking immediate dominators</li>
  <li><strong>Improvement</strong>: Added static <a href="https://api.binary.ninja/cpp/group__datarenderer.html#a3e0b7f9d1fa4fe5c9f167f907a2b7a2e"><code class="language-plaintext highlighter-rouge">DataRendererContainer::RenderLinesForData</code></a> as a replacement for the <a href="https://api.binary.ninja/cpp/group__datarenderer.html#aa65fddb0a39d276e3a798db3925d2164"><code class="language-plaintext highlighter-rouge">DataRenderer::RenderLinesForData</code></a> member function</li>
  <li><strong>Improvement</strong>: Consolidated the <a href="https://github.com/Vector35/binaryninja-api/commit/3521487681389ee96e0b4e78d127a748d8eedd5e">C++, Python</a>, and Rust demangler APIs around a config-driven design</li>
  <li><strong>Improvement</strong>: Extended <a href="https://github.com/Vector35/binaryninja-api/commit/08e34ac325743085911f96b62c81d9a1f2127806">MLIL call instruction outputs to be expressions</a></li>
  <li><strong>Improvement</strong>: Improved <code class="language-plaintext highlighter-rouge">PyInitConfig</code> based Python initialization</li>
  <li><strong>Improvement</strong>: Integrated <a href="https://docs.binary.ninja/guide/types/cpp.html#template-simplifier">template simplification</a> into the structured GNU3/MSVC demanglers</li>
  <li><strong>Improvement</strong>: Made <a href="https://api.binary.ninja/cpp/group__databuffer.html#class_binary_ninja_1_1_data_buffer"><code class="language-plaintext highlighter-rouge">DataBuffer</code></a> implicitly convert to <code class="language-plaintext highlighter-rouge">std::span</code></li>
  <li><strong>Improvement</strong>: Made <code class="language-plaintext highlighter-rouge">DefaultWebsocketClient::connect</code> asynchronous instead of blocking</li>
  <li><strong>Improvement</strong>: Made basic block accessors lock-free for the C API</li>
  <li><strong>Improvement</strong>: <a href="https://github.com/Vector35/binaryninja-api/commit/c0b746af212f4458c632af421760fe5b26e1f7df">Migrated Python demangler bindings</a> to route through the <a href="https://api.binary.ninja/cpp/struct_binary_ninja_1_1_demangler_config.html"><code class="language-plaintext highlighter-rouge">DemanglerConfig</code></a>/<a href="https://api.binary.ninja/binaryninja.demangle-module.html#binaryninja.demangle.DemangleResult"><code class="language-plaintext highlighter-rouge">DemangleResult</code></a> C API, with structured template simplification support</li>
  <li><strong>Improvement</strong>: Refactored the <a href="https://github.com/Vector35/binaryninja-api/commit/261324f6c8f540283790a62c2fd1fb6b1e88439a">MSVC demangler</a> to parse symbols into structured type nodes before finalization</li>
  <li><strong>Improvement</strong>: Removed <a href="https://github.com/Vector35/binaryninja-api/commit/c3cdbb068e09f311e2a3d154327ba9640ce2f0d7">unused path manipulation functions from the C API</a></li>
  <li><strong>Improvement</strong>: Replaced <a href="https://github.com/Vector35/binaryninja-api/commit/9621ce3c2ee5000f431e9a6ae80cf05476715801"><code class="language-plaintext highlighter-rouge">NotImplemented</code></a> in <a href="https://api.binary.ninja/cpp/group__architectures.html#class_binary_ninja_1_1_architecture"><code class="language-plaintext highlighter-rouge">Architecture</code></a> patch methods with default values or errors</li>
  <li><strong>Improvement</strong>: Replaced the <code class="language-plaintext highlighter-rouge">isAuto</code> parameter of <a href="https://api.binary.ninja/cpp/group__binaryview.html#af49d128b1539caf1100f2ede3383af00"><code class="language-plaintext highlighter-rouge">BinaryView::StoreMetadata</code></a> to allow persisting metadata without marking the file as modified</li>
  <li><strong>Improvement</strong>: Updated <code class="language-plaintext highlighter-rouge">bnpython3</code> to read from stdin when the input file is <code class="language-plaintext highlighter-rouge">-</code></li>
  <li><strong>Improvement</strong>: Updated <a href="https://github.com/Vector35/binaryninja-api/commit/45f8df2d88913212e8b577d3f50196e96e2780ed">core demangle APIs to use registered demanglers</a></li>
  <li><strong>Fix</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/a8df9061c974a9315fe2f97f3ee2a776ddad97dc">missing fields</a> to <a href="https://api.binary.ninja/cpp/group__core.html#struct_b_n_license_addon"><code class="language-plaintext highlighter-rouge">BNLicenseAddon</code></a></li>
  <li><strong>Fix</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/0a626589144ad46dca1934f3ab869b57a111c17c">missing initialization calls in the Python API</a></li>
  <li><strong>Fix</strong>: Fixed Python <a href="https://api.binary.ninja/cpp/group__binaryview.html#class_binary_ninja_1_1_metadata"><code class="language-plaintext highlighter-rouge">Metadata</code></a> object comparisons to use <a href="https://api.binary.ninja/cpp/group__core.html#gab2222944ea385c76dd84ca3fea5750f6"><code class="language-plaintext highlighter-rouge">BNMetadataIsEqual</code></a></li>
  <li><strong>Fix</strong>: Fixed Shiboken warnings caused by bad enum conversions in the Python API</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/9fa5ec76c4729555221901fb2ed57473f030ed6e">GNU3 demangler template and backref handling</a> by using shared type nodes for substitutions and nested names</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/8153"><code class="language-plaintext highlighter-rouge">Function.set_user_inline_during_analysis</code></a> raising a <code class="language-plaintext highlighter-rouge">TypeError</code> instead of setting the value</li>
  <li><strong>Fix</strong>: Fixed <a href="https://api.binary.ninja/cpp/group__coreapi.html#gabdf34737f262570740fd9322b2ba17dc"><code class="language-plaintext highlighter-rouge">GetSystemCacheDirectory</code></a> to use the documented paths</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/8516ebe292a52e5da28fcc57137308cea46192b2"><code class="language-plaintext highlighter-rouge">LowLevelILFunction::AddOverflow</code></a> to store its operands in the correct fields of the expression</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/1653"><code class="language-plaintext highlighter-rouge">demangle_ms</code> returning invalid types and mishandling attributes</a> for vftables, multiple inheritance, and parameterless functions</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/2e89fe24b633b291726bf25c7291f2acd089f886">leaks caused by unclear ownership of <code class="language-plaintext highlighter-rouge">Menu</code> instances</a></li>
  <li><strong>Fix</strong>: Fixed <code class="language-plaintext highlighter-rouge">Make Enum</code> storing concrete types instead of named type references</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/6326257649265907739832337316637601819417"><code class="language-plaintext highlighter-rouge">Metadata::operator==</code></a> to perform a value comparison instead of a pointer comparison</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/8166"><code class="language-plaintext highlighter-rouge">SESSION_COUNT</code> not incrementing</a> when cloning a <a href="https://api.binary.ninja/cpp/group__logview.html#ab7739865c4dfb446cdd1817048e9513d"><code class="language-plaintext highlighter-rouge">Session</code></a></li>
  <li><strong>Fix</strong>: Fixed <code class="language-plaintext highlighter-rouge">_inline_during_analysis_with_confidence</code> not converting <a href="https://api.binary.ninja/binaryninja.types-module.html#binaryninja.types.InlineDuringAnalysisWithConfidence"><code class="language-plaintext highlighter-rouge">InlineDuringAnalysisWithConfidence</code></a> in the Python API</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/e1ebfcd751ee5933da99bb21606b779edfe440b2"><code class="language-plaintext highlighter-rouge">copy_expr_to</code> and added builder methods</a> for recently-added instructions in the Python API</li>
  <li><strong>Fix</strong>: Fixed a <a href="https://github.com/Vector35/binaryninja-api/commit/d84828cb674d8fad4a2474212026df0a38eef9a8">crash</a> when registering an <a href="https://api.binary.ninja/cpp/group__architectures.html#class_binary_ninja_1_1_architecture"><code class="language-plaintext highlighter-rouge">Architecture</code></a> or <a href="https://api.binary.ninja/cpp/group__architectures.html#class_binary_ninja_1_1_architecture_hook"><code class="language-plaintext highlighter-rouge">ArchitectureHook</code></a> multiple times in Python</li>
  <li><strong>Fix</strong>: Fixed a <a href="https://github.com/Vector35/binaryninja-api/issues/8084"><code class="language-plaintext highlighter-rouge">NameError</code></a> in <a href="https://api.binary.ninja/binaryninja.languagerepresentation-module.html#binaryninja.languagerepresentation.LanguageRepresentationFunction.get_block_lines"><code class="language-plaintext highlighter-rouge">get_block_lines</code></a> caused by referencing an undefined <code class="language-plaintext highlighter-rouge">instr</code> variable instead of <a href="https://api.binary.ninja/binaryninja.highlevelil-module.html#binaryninja.highlevelil.HighLevelILFunction.block"><code class="language-plaintext highlighter-rouge">block</code></a></li>
  <li><strong>Fix</strong>: Fixed a <a href="https://github.com/Vector35/binaryninja-api/commit/68215ea14cfbaa4966f830d85d98f7f49b416455">memory leak in the Python API</a> where <a href="https://api.binary.ninja/cpp/group__core.html#ga73d78e9d53982c845ada3331274d6a70"><code class="language-plaintext highlighter-rouge">BNParseExpression</code></a> errors weren’t freed with <a href="https://api.binary.ninja/cpp/group__core.html#gaea259ee27eb417da8b7d16dc9b488d7c"><code class="language-plaintext highlighter-rouge">BNFreeParseError</code></a></li>
  <li><strong>Fix</strong>: Fixed a parameter swap bug in <code class="language-plaintext highlighter-rouge">IsSSAVarLiveAt</code> for MLIL SSA that caused incorrect liveness results</li>
  <li><strong>Fix</strong>: Fixed a potential crash caused by an invalid <a href="https://api.binary.ninja/cpp/group__filecontext.html#class_file_context"><code class="language-plaintext highlighter-rouge">FileContext</code></a> current frame during close</li>
  <li><strong>Fix</strong>: Fixed an overflow error in Shiboken on Linux when converting <code class="language-plaintext highlighter-rouge">uint64_t</code> values greater than <code class="language-plaintext highlighter-rouge">INT64_MAX</code></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/b99850165454f6012f7c2c61468e75beb61df367">custom demangler dispatch on Python 3.14</a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/8284">demanglers failing to compile on the API side due</a> to an include on core-only <code class="language-plaintext highlighter-rouge">unicode.h</code></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/73bd58d4e69cf0fc19c1ec47445eb008e74347ea">exceptions</a> from <code class="language-plaintext highlighter-rouge">__del__</code> on <a href="https://api.binary.ninja/binaryninja.types-module.html#binaryninja.types.StructureType"><code class="language-plaintext highlighter-rouge">StructureType</code></a>, <a href="https://api.binary.ninja/binaryninja.types-module.html#binaryninja.types.EnumerationType"><code class="language-plaintext highlighter-rouge">EnumerationType</code></a>, and <code class="language-plaintext highlighter-rouge">NamedTypeReferenceType</code> during Python interpreter shutdown</li>
  <li><strong>Fix</strong>: Fixed handling of <a href="https://api.binary.ninja/binaryninja.debugger.debuggercontroller-module.html#binaryninja.debugger.debuggercontroller.DebuggerController.modules"><code class="language-plaintext highlighter-rouge">modules</code></a> parameter when passed as either a list or a string</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/5a7ab29fcf3f8389e1546ec7db0819cc77c1dfc9">handling of no-type results in the demangler</a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/424dc721f5f2a3a7ffd5a6ccbcc7320b5ae7496d">handling of zero-width types returned</a> by a custom <a href="https://api.binary.ninja/cpp/class_binary_ninja_1_1_demangler.html"><code class="language-plaintext highlighter-rouge">Demangler</code></a> in the Python API</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/fd40266f767e51e649fb48376e25f47a60d79765">incorrect reference counting in the C++ API</a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/58fa98458b667eba3fc1cc1e71de15706765f3fe">leaks caused by missing parenting of Qt objects</a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/0a626589144ad46dca1934f3ab869b57a111c17c">missing initialization in several APIs</a> that could leave objects in an uninitialized state</li>
  <li><strong>Fix</strong>: Fixed the <a href="https://github.com/Vector35/binaryninja-api/issues/7466">Visual C++ name demangler failing on certain mangled names</a>, such as those containing <code class="language-plaintext highlighter-rouge">@@@</code></li>
  <li><strong>Fix</strong>: Fixed the <a href="https://github.com/Vector35/binaryninja-api/issues/8130">Python API</a> missing <a href="https://api.binary.ninja/binaryninja.binaryview-module.html#binaryninja.binaryview.BinaryViewType.get_default_load_settings_for_data"><code class="language-plaintext highlighter-rouge">get_default_load_settings_for_data</code></a>, which was referenced in example code but never implemented</li>
  <li><strong>Fix</strong>: Fixed the <a href="https://github.com/Vector35/binaryninja-api/commit/aca1c6f63911057018341869b9aaf74f486a1474">stub generator to be less strict about leading indentation</a></li>
  <li><strong>Fix</strong>: Guarded against use of disposed <a href="https://api.binary.ninja/cpp/group__binaryview.html#class_binary_ninja_1_1_binary_view"><code class="language-plaintext highlighter-rouge">BinaryView</code></a> handles</li>
  <li><strong>Fix</strong>: Made <a href="https://github.com/Vector35/binaryninja-api/issues/8341"><code class="language-plaintext highlighter-rouge">loader.syntheticSectionBase</code> writable instead of read-only</a></li>
  <li><strong>Fix</strong>: Re-added the <a href="https://github.com/Vector35/binaryninja-api/commit/73976e975ddf4dd0cbb5aa49425cf36e5655cd5c">license text field</a> to the API</li>
  <li><strong>Fix</strong>: Replaced <a href="https://github.com/Vector35/binaryninja-api/commit/b4ccb82ea76b98457d9dc59424632ca412511ed4">bare <code class="language-plaintext highlighter-rouge">except:</code> clauses with <code class="language-plaintext highlighter-rouge">except Exception:</code></a> in the Python API to fix signal propagation</li>
</ul>

<h2 id="rust-api">Rust API</h2>

<ul>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/8fbf9ca9c0c32c600008dc6d85cacf84276736f8">Rust APIs for custom function lifters</a></li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/beee8650a717b65a047612bca530dbc55499ec08"><code class="language-plaintext highlighter-rouge">FlowGraphLayout</code> and accompanying APIs</a> for custom flow graph layouts to the Rust API</li>
  <li><strong>Feature</strong>: Added a <a href="https://github.com/Vector35/binaryninja-api/commit/01b8ec1056e5b05c8d612d1a7ea32c0efb16813c"><code class="language-plaintext highlighter-rouge">transform</code> module to the Rust API</a></li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/61359968bab782ba9283ed124f12e1b5569725f5">support for owned <code class="language-plaintext highlighter-rouge">Settings</code> handles in the Rust API</a></li>
  <li><strong>Improvement</strong>: Migrated the <a href="https://github.com/Vector35/binaryninja-api/commit/d46c79b22ff78cfff7c907acaae1ccba2e5b3580">Rust demangler bindings</a> and consumers to the new C contract</li>
  <li><strong>Improvement</strong>: Removed the <a href="https://github.com/Vector35/binaryninja-api/commit/c4ba6d79ae3b96d56cc6b3744e7c64e004ecd161"><code class="language-plaintext highlighter-rouge">BinaryViewExt</code> trait and its blanket impl</a> from the <code class="language-plaintext highlighter-rouge">binary_view</code> module</li>
  <li><strong>Improvement</strong>: Refactored the <a href="https://github.com/Vector35/binaryninja-api/commit/a68be26dd8c84ad661909e5f4547ba812ccd81e7">default implementation of <code class="language-plaintext highlighter-rouge">BinaryViewBase::save</code></a> to save raw file contents</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/043739ad3c5a63019ff2d350befbd8bf3db446c2">Rust plugin dSYMs</a> not preserving native debug symbols for C/C++ dependencies</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/7472"><code class="language-plaintext highlighter-rouge">Activity::new_with_action</code></a> in the Rust API storing a stack pointer to the callback closure, causing use-after-free when the closure captured variables</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/73c8554b8d5d460ed8fc331e787b9b272882e9b1"><code class="language-plaintext highlighter-rouge">load_with_options_and_progress</code></a> to correctly accept <code class="language-plaintext highlighter-rouge">None</code> for <code class="language-plaintext highlighter-rouge">options</code></li>
  <li><strong>Fix</strong>: Fixed a <a href="https://github.com/Vector35/binaryninja-api/issues/8028">missing operand field when round-tripping text tokens</a> in the Rust API</li>
  <li><strong>Fix</strong>: Fixed a <a href="https://github.com/Vector35/binaryninja-api/commit/be20cd873bbe776ef85d5a9a1f6547b43fb39d59">use-after-free in <code class="language-plaintext highlighter-rouge">Function::set_int_display_type</code></a> in the Rust API</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/698780be936560dc11a19b80d0236f80d9753b42">improper use of <code class="language-plaintext highlighter-rouge">Ref&lt;T&gt;</code></a> in collaboration project function signatures in the Rust API</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/82f6cd81d2cc09abf4a3ad30e2ce4404ced050a3">off-by-one accesses to operand lists</a> in <code class="language-plaintext highlighter-rouge">MediumLevelILInstruction::lift</code> that could cause a crash or incorrect data being read</li>
  <li><strong>Fix</strong>: Fixed the <a href="https://github.com/Vector35/binaryninja-api/commit/a68be26dd8c84ad661909e5f4547ba812ccd81e7">Rust <code class="language-plaintext highlighter-rouge">save</code> bindings for custom binary views</a></li>
  <li><strong>Fix</strong>: Removed an unused dependency on <code class="language-plaintext highlighter-rouge">libdbus</code> from the Rust secrets provider</li>
  <li><strong>Fix</strong>: Renamed <a href="https://github.com/Vector35/binaryninja-api/commit/be46729666a47a71cc1cd5d263b5c6e9e96ec6c3"><code class="language-plaintext highlighter-rouge">Settings::new</code> to <code class="language-plaintext highlighter-rouge">Settings::global</code> in the Rust API</a> to remove a foot gun</li>
</ul>

<h2 id="debugger-1">Debugger</h2>

<ul>
  <li><strong>Improvement</strong>: <a href="https://github.com/Vector35/debugger/commit/f06685550afc4b43ab898ffa7b601bb365d6615b">Disabled the <code class="language-plaintext highlighter-rouge">debugger.useMemoryMapSegments</code> setting</a> by default</li>
  <li><strong>Improvement</strong>: <a href="https://github.com/Vector35/debugger/issues/1109">Remembered the last checked access types</a> in the TTD next/prev memory access dialog</li>
  <li><strong>Improvement</strong>: Rendered debugger dependencies in a readable format instead of a single-line JSON blob</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/debugger/commit/dfc50be87094d63d9eba3f7dfb1f33ffd95a7320">LLDB version detection on macOS and Linux</a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/debugger/commit/accb6acc901396f34b85ba066eb4915ddac07054">TTD sidebar widgets showing on non-TTD platforms</a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/debugger/commit/14a179d345f9e1e89edce59b08d2d9c7227e080d">TTD target termination to occur on the engine thread</a></li>
  <li><strong>Fix</strong>: Fixed a <a href="https://api.binary.ninja/binaryninja.debugger.debuggercontroller-module.html#binaryninja.debugger.debuggercontroller.DebuggerController"><code class="language-plaintext highlighter-rouge">DebuggerController</code></a> reference leak caused by <code class="language-plaintext highlighter-rouge">AttachProcessDialog</code></li>
  <li><strong>Fix</strong>: Fixed a <a href="https://github.com/Vector35/debugger/commit/0664841308c7657e70afc309bda96fdcc5ba528a"><code class="language-plaintext highlighter-rouge">null</code> pointer crash in <code class="language-plaintext highlighter-rouge">DebuggerUI::CreateForViewFrame</code></a> when <a href="https://api.binary.ninja/cpp/group__uicontext.html#class_u_i_context"><code class="language-plaintext highlighter-rouge">UIContext::contextForWidget</code></a> returned <code class="language-plaintext highlighter-rouge">null</code></li>
  <li><strong>Fix</strong>: Fixed a <a href="https://github.com/Vector35/debugger/commit/2d68ef3fa07c55cc36f32b948dd281107c7f9afe"><code class="language-plaintext highlighter-rouge">strdup</code> memory leak in <code class="language-plaintext highlighter-rouge">GetPathBaseName</code></a></li>
  <li><strong>Fix</strong>: Fixed a <a href="https://github.com/Vector35/debugger/commit/6229b345fc820a1125d4798d2cecde40a630d459">bounds check issue in RLE decoding (<code class="language-plaintext highlighter-rouge">DecodeRLE</code>)</a></li>
  <li><strong>Fix</strong>: Fixed a <a href="https://github.com/Vector35/debugger/issues/1052">bug where deleted debugger controllers were nulled instead of erased</a> from the controller list</li>
  <li><strong>Fix</strong>: Fixed a <a href="https://github.com/Vector35/debugger/commit/883348ebde6e5e85297f9dc695dd4f79ba3a97f9">crash caused</a> by <a href="https://api.binary.ninja/binaryninja.debugger.debuggercontroller-module.html#binaryninja.debugger.debuggercontroller.DebuggerController"><code class="language-plaintext highlighter-rouge">DebuggerController</code></a> being freed while detached worker threads for <code class="language-plaintext highlighter-rouge">Launch</code>/<code class="language-plaintext highlighter-rouge">Attach</code>/<code class="language-plaintext highlighter-rouge">Connect</code>/<code class="language-plaintext highlighter-rouge">Go</code>/<code class="language-plaintext highlighter-rouge">Step*</code>/<code class="language-plaintext highlighter-rouge">RunTo*</code>/<code class="language-plaintext highlighter-rouge">Restart</code>/<code class="language-plaintext highlighter-rouge">Detach</code> were still running</li>
  <li><strong>Fix</strong>: Fixed a <a href="https://github.com/Vector35/debugger/commit/ffcb34844e2d1696b0b351f8c7267bf187eaf19c">crash in <code class="language-plaintext highlighter-rouge">CorelliumAdapter::BreakInto</code></a> when <code class="language-plaintext highlighter-rouge">m_rspConnector</code> is null</li>
  <li><strong>Fix</strong>: Fixed a <a href="https://github.com/Vector35/debugger/commit/c0598f605541ae9d36ef1f5abfdadd347e560f6a">crash when reading stack variable parameters for calls</a> in the debugger IL views</li>
  <li><strong>Fix</strong>: Fixed a <a href="https://github.com/Vector35/debugger/commit/b35e2780e70bbe15fb9b2d7fab52e9d0f1240618">leftover debug thread not being joined</a> in the <code class="language-plaintext highlighter-rouge">WindowsNativeAdapter</code> destructor when a debugged process exits on its own</li>
  <li><strong>Fix</strong>: Fixed a <a href="https://github.com/Vector35/debugger/commit/2ed559b91898b889e798b27c21041c365fde6f73">null pointer dereference in <code class="language-plaintext highlighter-rouge">DbgEngAdapter::ReadMemory</code></a> and <code class="language-plaintext highlighter-rouge">WriteMemory</code></li>
  <li><strong>Fix</strong>: Fixed a <a href="https://github.com/Vector35/debugger/commit/a461c281521d001b7cc32fd6374acd794050b700">null pointer dereference in <code class="language-plaintext highlighter-rouge">EsrevenAdapter::GetProcessList</code></a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/debugger/commit/bd0767c810eae5e7b354f3b69c595d65ea1bf5b3">crashes from missing null checks on <code class="language-plaintext highlighter-rouge">m_rspConnector</code></a> in <code class="language-plaintext highlighter-rouge">WriteMemory</code> and TTD call query</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/debugger/commit/c89569f42dc2dd78b062bb71cfe2898d9a4ce9d4">potential crash from missing <code class="language-plaintext highlighter-rouge">nullptr</code> checks on returns</a> from the LLDB API</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/debugger/commit/3aa8771e8937d5b23b95109f95a1ccadbf18c444">several memory leaks in the debugger</a></li>
  <li><strong>Fix</strong>: Fixed the <a href="https://github.com/Vector35/debugger/commit/295e077934fb867edaced17b16d5ebf6c18391eb">debugger throwing an exception when parsing certain integers</a> in the remote protocol</li>
  <li><strong>Fix</strong>: <a href="https://github.com/Vector35/debugger/issues/910">Rejected a TTD launch when no trace was specified</a></li>
  <li><strong>Fix</strong>: Removed a <a href="https://github.com/Vector35/debugger/commit/9494abf72d599ea17a6b6fd050918b159698bf55">redundant 100x <code class="language-plaintext highlighter-rouge">Release()</code> loop</a> from the DbgEng adapters’ <code class="language-plaintext highlighter-rouge">Reset()</code></li>
</ul>

<h2 id="documentation">Documentation</h2>

<ul>
  <li><strong>Feature</strong>: Added an <a href="https://github.com/Vector35/binaryninja-api/commit/06c0905093b1b19da7dcc7f74fe3f0eccec9a59d">example plugin</a> that recognizes and displays Rust string slices</li>
  <li><strong>Improvement</strong>: Documented <a href="https://github.com/Vector35/binaryninja-api/issues/6712">side-by-side installs</a></li>
  <li><strong>Improvement</strong>: Documented the difference between <code class="language-plaintext highlighter-rouge">Forget This File</code> and <a href="https://docs.binary.ninja/guide/index.html#recent-files"><code class="language-plaintext highlighter-rouge">Remove From Recent Files</code></a></li>
  <li><strong>Improvement</strong>: Documented the <a href="https://github.com/Vector35/binaryninja-api/commit/7fb6815b68f1806b6176b2114046d7e69e12a478">difference between unimplemented and unknown <code class="language-plaintext highlighter-rouge">LLIL</code> states</a></li>
  <li><strong>Improvement</strong>: Documented the <a href="https://github.com/Vector35/debugger/commit/a37e8fea484c248e0ac84afb2bd1ccdbc3f685aa">target memory map being mirrored as segments</a></li>
  <li><strong>Improvement</strong>: Improved <a href="https://github.com/Vector35/binaryninja-api/commit/1087a554d4046bb334cbdfd6586e643edc586e22">documentation for context-aware control-flow recovery</a>, lifting, and disassembly</li>
  <li><strong>Improvement</strong>: Improved the <a href="https://github.com/Vector35/binaryninja-api/commit/5b241b6ece6feead4932d6735d8b5b9abf178d5">large file section</a> of the <a href="https://docs.binary.ninja/guide/troubleshooting.html#working-with-large-or-complex-binaries">troubleshooting documentation</a></li>
  <li><strong>Improvement</strong>: Made the <a href="https://github.com/Vector35/binaryninja-api/issues/7867">sidebar navigation collapsible</a> in the Python API docs</li>
  <li><strong>Fix</strong>: Corrected the <a href="https://docs.binary.ninja/guide/kernelcache.html#support-matrix">kernel cache support matrix</a>, which incorrectly listed support for iOS versions predating <code class="language-plaintext highlighter-rouge">MH_FILESET</code></li>
  <li><strong>Fix</strong>: Fixed the <a href="https://github.com/Vector35/binaryninja-api/commit/714af099b1d4110d82bb29aecc181da5a00a25b8"><code class="language-plaintext highlighter-rouge">multitool.py</code> file download example</a> to actually save the downloaded file</li>
</ul>

<h2 id="other">Other</h2>

<ul>
  <li><strong>Feature</strong>: Allowed <a href="https://github.com/Vector35/binaryninja-api/commit/5037372580044681979203921811749926216299">opening databases without opening a file</a></li>
  <li><strong>Improvement</strong>: Changed linker behavior to more closely match <code class="language-plaintext highlighter-rouge">gcc</code></li>
  <li><strong>Improvement</strong>: <a href="https://github.com/Vector35/binaryninja-api/commit/6c34643b639607d7c0a652300bbdbc261fbe2388">Compiled <code class="language-plaintext highlighter-rouge">jsoncpp</code> into a separate namespace</a> when built as part of core, allowing it to be included in statically linked builds</li>
  <li><strong>Improvement</strong>: Improved <a href="https://docs.binary.ninja/guide/migration/migrationguideida.html">IDB (IDA Pro database)</a> file support</li>
  <li><strong>Improvement</strong>: Renamed the <a href="https://github.com/Vector35/binaryninja-api/issues/8089"><code class="language-plaintext highlighter-rouge">BNTL</code> commands root to <code class="language-plaintext highlighter-rouge">Type Library</code></a></li>
  <li><strong>Improvement</strong>: Updated <a href="https://github.com/Vector35/binaryninja-api/commit/c2da6053eebedcabce02529ff19f8cf694e5efb4">to Qt 6.11.1, raising the minimum PySide Python version</a> to <code class="language-plaintext highlighter-rouge">3.10</code></li>
  <li><strong>Improvement</strong>: Updated to <code class="language-plaintext highlighter-rouge">LLVM 22.1.8</code> and raised the minimum supported Python version</li>
  <li><strong>Fix</strong>: Enabled creation of <code class="language-plaintext highlighter-rouge">.pyc</code> files in the system cache directory</li>
  <li><strong>Fix</strong>: Fixed <code class="language-plaintext highlighter-rouge">Zstd</code> decompression of files with multiple concatenated frames</li>
  <li><strong>Fix</strong>: Fixed <code class="language-plaintext highlighter-rouge">sys.executable</code> not being properly set for <code class="language-plaintext highlighter-rouge">bnpython3</code></li>
  <li><strong>Fix</strong>: Fixed a crash on startup caused by a malformed <code class="language-plaintext highlighter-rouge">settings.json</code></li>
  <li><strong>Fix</strong>: Fixed a deadlock on quit between <code class="language-plaintext highlighter-rouge">RunGuard</code> teardown and the URL handler thread</li>
  <li><strong>Fix</strong>: Fixed crashes caused by unsafe use of <code class="language-plaintext highlighter-rouge">printf</code>-style logging calls</li>
  <li><strong>Fix</strong>: Fixed incorrect Python code signing on macOS</li>
  <li><strong>Fix</strong>: Fixed missing Python entitlement on macOS</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/6e4bc5a61803ceec742f5570b940bf7bf9f2d201">normalization of the <code class="language-plaintext highlighter-rouge">virtualenv</code> path setting</a></li>
  <li><strong>Fix</strong>: Fixed potential crash in <a href="https://api.binary.ninja/cpp/group__core.html#gafb8bf891e6db3628ab06c6c4f35a9347"><code class="language-plaintext highlighter-rouge">BNPathExists</code></a>, <a href="https://api.binary.ninja/cpp/group__core.html#gae0f5ee2a585a8cf8e055e40befaca521"><code class="language-plaintext highlighter-rouge">BNIsPathDirectory</code></a>, and <code class="language-plaintext highlighter-rouge">BNIsPathRegularFile</code> when the filesystem operation throws an exception</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/issues/8101">update channel detection</a> to use manifests instead of hard-coded GUIDs</li>
</ul>

<p>With such a large release, we’ve done more than even the list shown here. For even more details, check out our <a href="https://github.com/Vector35/binaryninja-api/milestone/31?closed=1">closed milestone</a> on GitHub.</p>]]></content><author><name>Jordan Wiens</name><email>jordan@vector35.com</email></author><category term="announcements" /><category term="stable" /><summary type="html"><![CDATA[Binary Ninja 6.0 (Krypton) is here! This is a major version bump, and it’s worth the wait. We’ve shipped a brand new MCP server, a new Binary Similarity feature, and a complete overhaul of the Plugin Manager as the new Extension Manager. Under the hood, you’ll find major improvements to performance and memory usage, a refactored calling convention to properly represent structure parameters and return values, and added HLIL structure initializers. On the scripting side, we’ve updated the bundled Python version to 3.13 and included it on Linux. We’ve also added a new TMS320C6x architecture, a new user wizard to ease migration, and a long list of debugger improvements. And those are still only some of the new features detailed below. We’re also improving the free edition. We’ve added the highly requested armv8 (AArch64) architecture as well as the above-mentioned MCP server. Additionally, we’re also shipping a new Linux ARM64 build of the free version. Next, as previously announced, with this release we’re putting our new pricing and packaging into effect. Finally, thanks to everyone who participated in our 10 year celebration! We’re looking forward to another decade!]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://binary.ninja/blog/images/6.0-release/krypton.jpg" /><media:content medium="image" url="https://binary.ninja/blog/images/6.0-release/krypton.jpg" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">The Binary Hiding in Your Registry: Cracking Windows UCPD’s Dynamic Rules</title><link href="https://binary.ninja/2026/08/04/ucpd-dynamic-rules.html" rel="alternate" type="text/html" title="The Binary Hiding in Your Registry: Cracking Windows UCPD’s Dynamic Rules" /><published>2026-08-04T13:37:00+00:00</published><updated>2026-08-04T13:37:00+00:00</updated><id>https://binary.ninja/2026/08/04/ucpd-dynamic-rules</id><content type="html" xml:base="https://binary.ninja/2026/08/04/ucpd-dynamic-rules.html"><![CDATA[<p>Is Microsoft shipping a hidden binary to your computer – inside the registry?</p>

<p>A few weeks ago I was watching <a href="https://www.youtube.com/watch?v=xQUYh4iKsB0">a YouTube video</a> that covered my earlier
research on the <a href="/2025/03/25/default-browser-upcd.html">UCPD driver</a>, and for a split second I saw a registry key that I
have been searching for an example of for some time. I contacted the video’s author and obtained the key from his
machine. It was Base64 encoded and to my surprise, once I decoded it, it started with <code class="language-plaintext highlighter-rouge">MZ</code>.</p>

<p>Sure enough, it’s a valid Windows executable sitting inside a registry key. This post is the story of both taking it apart
as well as the bug I found that means the whole mechanism is dead anyway.</p>

<!--more-->

<h2 id="a-quick-refresher-on-ucpd">A Quick Refresher on UCPD</h2>

<p>If you have not read my <a href="/2025/03/25/default-browser-upcd.html">earlier post on UCPD</a>, here is the short version.</p>

<p>UCPD stands for User Choice Protection Driver and its entire job is to protect your default browser choice. On Windows,
setting the default browser used to be a matter of writing a registry key with the correct hash. UCPD put a stop to that:
now, only the Windows Settings app is allowed to do it and the driver specifically blocks a list of Microsoft’s own
utilities like <code class="language-plaintext highlighter-rouge">reg.exe</code>, <code class="language-plaintext highlighter-rouge">powershell.exe</code>, <code class="language-plaintext highlighter-rouge">rundll32.exe</code> that could otherwise be tricked into modifying the setting.</p>

<p>Browser vendors (and spyware/adware authors!) were not thrilled. They found workarounds, Microsoft tightened the driver,
they found new workarounds, and so on. I covered that cat-and-mouse game in the blog post above and in a <a href="https://youtu.be/TheUdURzFjI">lightning talk
at RE//verse 2025</a> already, so I won’t rehash it here.</p>

<p>There was one loose end from that research, though. Buried in the driver is a code path that loads some configuration
from this registry key:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UCPD\DR
</code></pre></div></div>

<p>Unfortunately, I couldn’t analyze it because on every machine and VM I have, the key is empty.</p>

<h2 id="a-pe-with-no-code">A PE with No Code</h2>

<p>We can see from the FlyTech video
<a href="https://youtu.be/xQUYh4iKsB0?t=381">“Microsoft Added This Driver to Windows and Said Nothing”</a>, that on his
machine, <code class="language-plaintext highlighter-rouge">DR</code> had a value. He read <code class="language-plaintext highlighter-rouge">DR</code> as “Disaster Recovery,” which, as we’ll see below, is probably not the case.</p>

<p>FlyTech is based in Europe, which could explain why he has the key set. The entire UCPD saga grew out of the EU browser
choice rules, so it would not be surprising if Microsoft only pushes these policy blobs to European users. To be clear
though, this is only a guess.</p>

<p>As mentioned earlier, after we Base64 decode it, it is a PE file.</p>

<p>So: is Microsoft running a binary on your machine behind your back?</p>

<p>No. And that relates to the first interesting thing about this file. I opened it in Binary Ninja and there is no
code in it at all. This is not a parsing bug – it only has a tiny <code class="language-plaintext highlighter-rouge">.rdata</code> section containing
what looks like encrypted data, plus an Authenticode certificate at the end of the file.</p>

<div class="language-python highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="o">&gt;&gt;&gt;</span> <span class="nf">list</span><span class="p">(</span><span class="n">bv</span><span class="p">.</span><span class="n">functions</span><span class="p">)</span>
<span class="p">[]</span>
</code></pre></div></div>

<p>But why wrap data in a PE at all, if nothing is ever going to execute it?</p>

<p>Presumably, by packaging the payload as a signed PE, Microsoft gets to reuse the entire Authenticode code-signing
infrastructure for free and the driver can verify that only Microsoft could have produced this blob before it acts on
the contents. This is actually a very sensible design decision. You really don’t want a kernel driver consuming policy
from a registry key that any administrator could overwrite.</p>

<p>Now that I have both halves of the puzzle – the encrypted blob and the code that decrypts it – we can finally figure
out what it does.</p>

<h2 id="reversing-the-loader">Reversing the Loader</h2>

<p>This driver is quite easy to reverse because every stage logs an ETW event with a descriptive tag of the action.
Reading top to bottom, <code class="language-plaintext highlighter-rouge">process_DR</code> does exactly what you would expect:</p>

<table>
  <thead>
    <tr>
      <th>#</th>
      <th>log tag</th>
      <th>what it does</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>1</td>
      <td><code class="language-plaintext highlighter-rouge">Base64Decode</code></td>
      <td>REG_SZ string to PE bytes</td>
    </tr>
    <tr>
      <td>2</td>
      <td><code class="language-plaintext highlighter-rouge">ParsePEFormat</code></td>
      <td>locate the <code class="language-plaintext highlighter-rouge">.rdata</code> blob</td>
    </tr>
    <tr>
      <td>3</td>
      <td><code class="language-plaintext highlighter-rouge">CalculatePEHashInMem</code></td>
      <td>hash the in-memory PE</td>
    </tr>
    <tr>
      <td>4</td>
      <td><code class="language-plaintext highlighter-rouge">CertificateVerify</code></td>
      <td>signature gate – only Microsoft-signed policy is accepted</td>
    </tr>
    <tr>
      <td>5</td>
      <td><code class="language-plaintext highlighter-rouge">DecryptData</code></td>
      <td>decrypt the blob</td>
    </tr>
    <tr>
      <td>6</td>
      <td><code class="language-plaintext highlighter-rouge">DispatcherConfig</code></td>
      <td>parse and dispatch the decrypted records</td>
    </tr>
  </tbody>
</table>

<!-- SCREENSHOT: process_DR in Binary Ninja HLIL, with the ETW log tag strings visible at each stage -->
<p><img src="/blog/images/ucpd-dr/process-dr-pipeline.png" alt="The driver narrating its own pipeline" class="image max-height-600" /></p>

<p>Stage 5 is the one I cared about. I asked <a href="https://sidekick.binary.ninja/">Sidekick</a>, our AI assistant, to reverse the
decryption function. Its answer: this is a custom XOR stream cipher. A hash function derives a set of seeds from the
key, those seeds generate a keystream, and the keystream gets XORed against the ciphertext. Nothing exotic.</p>

<p>It also renamed everything as it went: <code class="language-plaintext highlighter-rouge">expand_key_state</code>, <code class="language-plaintext highlighter-rouge">derive_keystream</code>, and the two mixing functions. That turned
the wall of <code class="language-plaintext highlighter-rouge">sub_140004xxx</code> calls into something you can actually read. I had a quick glance at the code and it seemed
correct.</p>

<p><img src="/blog/images/ucpd-dr/code-after-sidekick-markup.png" alt="The code after Sidekick markup" class="image max-height-600" /></p>

<h2 id="reimplementing-the-cipher">Reimplementing the Cipher</h2>

<p>Then I had Sidekick re-implement the whole thing in Python.</p>

<p>Before I could run the code, I noticed that the cipher needs a 32-byte key, but the function doesn’t have one baked in.
Thus, it has to come from the data itself.</p>

<p>Looking at the start of <code class="language-plaintext highlighter-rouge">.rdata</code>, it is not hard to see that it begins with a <code class="language-plaintext highlighter-rouge">u32</code> schema version of <code class="language-plaintext highlighter-rouge">0x3ec</code>, followed
by a <code class="language-plaintext highlighter-rouge">u32</code> of <code class="language-plaintext highlighter-rouge">0x238</code>, which looks exactly like the length of the ciphertext. If I take the next <code class="language-plaintext highlighter-rouge">0x20</code> bytes as the encryption key, the
remaining bytes in the section are exactly <code class="language-plaintext highlighter-rouge">0x238</code>. It all checks out! The layout is shown below:</p>

<!-- SCREENSHOT: Binary Ninja linear view of .rdata with the struct applied, showing header / size / key / ciphertext boundaries -->
<p><img src="/blog/images/ucpd-dr/rdata-layout.png" alt="The blob layout in .rdata" class="image max-height-600" /></p>

<p>I handed this to Sidekick and asked it to decrypt the blob. However, despite my high expectations, the result was
garbage:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>00000000: fe 2a 56 4a e3 ff fb 5b 9f 78 91 bd 2b d0 5c 59  .*VJ...[.x..+.\Y
00000010: 0d 92 1f e9 10 c0 44 8f 0a 2d c5 2d c8 b9 54 7d  ......D..-.-..T}
00000020: be bd 53 65 68 2b b4 08 63 f0 69 89 2e 4c a0 7a  ..Seh+..c.i..L.z
00000030: 2d ca 1c 50 75 00 80 09 f3 ef 41 8e 78 67 7f 49  -..Pu.....A.xg.I
00000040: f5 0a 1e f2 b1 49 05 b5 8e b2 51 2d 27 44 0f 1c  .....I....Q-'D..
00000050: 36 6f bc 39 8f cb 60 49 ee 1c 46 0e 16 a2 b1 91  6o.9..`I..F.....
00000060: 92 40 27 84 64 02 92 41 a2 ec a8 dc d1 4f 54 3f  .@'.d..A.....OT?
</code></pre></div></div>

<p>My first impression was that Sidekick blew it. So I asked Claude Code to redo it with Binary Ninja’s
<a href="https://dev-docs.binary.ninja/guide/mcp.html">MCP server</a>.
I deliberately only gave it the binary instead of the analysis database, so it could not be affected by Sidekick’s
renaming or type information.</p>

<p>This time it wrote another script, which produced the <em>exact same</em> garbage output. When challenged, it even brought
<a href="https://www.unicorn-engine.org/">Unicorn</a> in and emulated the code to argue that it had done everything correctly.</p>

<p>The chances of two AIs getting it wrong in exactly the same way seemed quite low, so I suspected something weird was
going on. I just couldn’t immediately tell what it was so I sat on it for a while.</p>

<h2 id="finding-the-right-hash">Finding the Right Hash</h2>

<p>After stewing on the problem some, I decided to Google several of the magic constants used in the cipher. This was how
we used to do things without AI! There were a few hits, and none of them appeared to be helpful. Then, out of pure luck,
I decided to search with DuckDuckGo, and this time I got a promising hit:
<a href="https://github.com/276793422/CalcHash_CS64"><code class="language-plaintext highlighter-rouge">CalcHash_CS64</code></a>. It appears to implement the same algorithm in C.</p>

<p>Still doubtful, I handed that to the AI anyway and asked it to see if it could get anywhere. And this time it actually
worked! The blob decrypts to something readable:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>00000000: 01 00 00 00 03 00 00 00 0c 00 00 00 28 02 00 00  ............(...
00000010: 01 00 00 00 f4 03 00 00 0c 00 00 00 18 02 00 00  ................
00000020: 0e 00 00 00 ee 03 00 00 0b 00 00 00 1a 00 00 00  ................
00000030: 2a 00 5c 00 64 00 6c 00 6c 00 68 00 6f 00 73 00  *.\.d.l.l.h.o.s.
00000040: 74 00 2e 00 65 00 78 00 65 00 ee 03 00 00 0b 00  t...e.x.e.......
00000050: 00 00 12 00 00 00 2a 00 5c 00 72 00 65 00 67 00  ......*.\.r.e.g.
00000060: 2e 00 65 00 78 00 65 00 ee 03 00 00 0b 00 00 00  ..e.x.e.........
</code></pre></div></div>

<p>And the only difference between the two versions is that <code class="language-plaintext highlighter-rouge">CalcHash_CS64</code> uses MD5 to derive the seeds, while our
reimplementation uses SHA-512. But UCPD’s code clearly uses SHA-512 to derive the seeds:</p>

<!-- SCREENSHOT: UCPD does use SHA-512 for seeds-->
<p><img src="/blog/images/ucpd-dr/ucpd-sha512.png" alt="UCPD uses SHA-512" class="image max-height-600" /></p>

<p>Here is what I <em>think</em> happened. At some point somebody at Microsoft looked at this code, saw MD5, and decided to harden
it with SHA-512. But they only changed the driver, and forgot to update the code that generates the ciphertext.</p>

<p>I don’t think the failure is silent, either. That <code class="language-plaintext highlighter-rouge">DecryptData</code> failure path is not a debug print, it is an ETW
telemetry event. So somewhere at Microsoft there should be a steady drip of decryption failures firing every time this
key is parsed. To be clear, I have not debugged a live machine to confirm that, but it is fairly clear from the code. If
you happen to work on UCPD at Microsoft: go check your telemetry!</p>

<p>With that said, AI did a great job but we’re not quite at AGI yet.</p>

<h2 id="what-is-in-the-dynamic-rules">What is in the Dynamic Rules</h2>

<p>We can see 14 program names from the decrypted blob:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>*\dllhost.exe    *\reg.exe       *\rundll32.exe   *\powershell.exe
*\regedit.exe    *\wscript.exe   *\cscript.exe    *\cmd.exe
*\InfDefaultInstall.exe          *\pwsh.exe       *\wmiprvse.exe
*\regini.exe     *\bssafe.exe    *\mshta.exe
</code></pre></div></div>

<p>If you read my first UCPD post, that list will look extremely familiar. These are Microsoft’s own signed binaries – they
pass the “is it signed by Microsoft” check trivially – so they get their own denylist. Otherwise flipping the default
browser would be as easy as asking <code class="language-plaintext highlighter-rouge">reg.exe</code> to do it for you, which defeats the purpose of the driver.</p>

<p>Now, why ship this in a registry key at all? The very same list of names is already hardcoded in <code class="language-plaintext highlighter-rouge">UCPD.sys</code>.</p>

<!-- SCREENSHOT: the same list of program names from UCPD.sys -->
<p><img src="/blog/images/ucpd-dr/ucpd-program-names.png" alt="Program names list from UCPD.sys" class="image max-height-600" /></p>

<p>Remember the key is called <strong>DR</strong>. I don’t believe it’s Disaster Recovery, but rather it stands for <strong>Dynamic
Rules</strong>. Changing the driver’s behavior normally means shipping a new <code class="language-plaintext highlighter-rouge">UCPD.sys</code>, and then getting users to install an update
and reboot. With this channel, Microsoft can push a policy update as a signed blob in a registry value and have it
take effect on the next load. It is similar to a definition update for an AV product.</p>

<p>And it is considerably more than a list. I had the AI reverse the dispatcher as well. The decrypted buffer is a nested
TLV tree – first a <code class="language-plaintext highlighter-rouge">u32</code> count, then records of <code class="language-plaintext highlighter-rouge">[type][value kind][length][payload]</code> – walked by a dispatcher that looks up
each type in a handler table populated at driver init. Five of them are registered:</p>

<table>
  <thead>
    <tr>
      <th>type</th>
      <th>name (from the ETW events)</th>
      <th>what it configures</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>1</td>
      <td><code class="language-plaintext highlighter-rouge">AntiInjection</code></td>
      <td>injection enforcement policy, 6 typed sub-fields</td>
    </tr>
    <tr>
      <td>2</td>
      <td><code class="language-plaintext highlighter-rouge">UIA</code></td>
      <td>UI Automation policy, a table of 32-byte entries</td>
    </tr>
    <tr>
      <td>3</td>
      <td><code class="language-plaintext highlighter-rouge">DenyListV1</code></td>
      <td>process patterns denied from touching protected keys</td>
    </tr>
    <tr>
      <td>4</td>
      <td><code class="language-plaintext highlighter-rouge">AllowListV1</code></td>
      <td>process patterns allowed, separate list and lock</td>
    </tr>
    <tr>
      <td>5</td>
      <td><code class="language-plaintext highlighter-rouge">StackTrace</code></td>
      <td>module names matched against the call stack of a write</td>
    </tr>
  </tbody>
</table>

<p>Our blob is a single type 3 record. Deny and allow are independent structures with separate locks, so a config can deny
broadly and then carve out exceptions. Each handler takes a lock, rebuilds its structure from scratch, and emits an ETW
event tagged with the rule name and a schema version.</p>

<p>For now the list it ships is identical to the one already compiled into the driver, so at the moment it changes nothing
– but the machinery is there for the day a browser vendor finds a new way around the protection.</p>

<p>I also wrote a <a href="https://kaitai.io/">Kaitai Struct</a>
<a href="https://github.com/xusheng6/ucpd_analysis/blob/main/202606_DR/ucpd_dr_config.ksy">definition</a> for it and rendered the
parsed tree directly in the Binary Ninja UI using our <a href="https://github.com/Vector35/kaitai">Kaitai UI plugin</a> (with a
<a href="https://github.com/Vector35/kaitai/tree/kaitai-ide-live-compile">patch</a>).</p>

<!-- SCREENSHOT: the Kaitai plugin pane in Binary Ninja showing the decrypted blob parsed into the nested TLV tree -->
<p><img src="/blog/images/ucpd-dr/kaitai-tree.png" alt="The decrypted config parsed with Kaitai in Binary Ninja" class="image max-height-600" /></p>

<h2 id="why-this-crypto-the-patent-hash">Why this Crypto? The “Patent Hash”</h2>

<p>The story could end here, but there is one more thread that ties everything together.</p>

<p>Throughout the analysis, the AI kept referring to the hash function as the “patent hash”. I assumed this was a
hallucination, but Microsoft holds an actual patent on this exact cipher:
<a href="https://patents.google.com/patent/US6570988B1/en">US 6,570,988 B1</a> (expired around 2020), “Simple technique for
implementing a cryptographic primitive using elementary register operations.”</p>

<p>And it is the same algorithm Windows uses to compute the <em>UserChoice association</em> hash.</p>

<p>Think back to the pre-UCPD world. Under the UserChoice key you had a program ID and a <code class="language-plaintext highlighter-rouge">Hash</code> value. That hash mixes your
username, the program ID, the extension or protocol, and a timestamp. If it does not validate, Windows ignores your
default and falls back to Edge. It is the tamper-evident layer that UCPD was later built to enforce in kernel mode. It
was reverse engineered by Christoph Kolbicz back in
<a href="https://kolbi.cz/blog/2017/10/25/setuserfta-userchoice-hash-defeated-set-file-type-associations-per-user/">2017</a>.
Firefox later <a href="https://searchfox.org/firefox-main/source/browser/components/shell/WindowsUserChoice.cpp">implemented the same
algorithm</a> so it could set
itself as the default browser without walking the user through Windows’ settings UI.</p>

<p>Now it is clear why Microsoft would roll their own cipher instead of just using AES: they didn’t quite. They had this
lying around from UserChoice, so they reused it.</p>

<h2 id="on-ai--re">On AI + RE</h2>

<p>There is no doubt that AI is getting better rapidly, and that more and more RE work can be handled by it. I still
remember the shock when I heard that at last year’s DEF CON finals, a team’s AI
<a href="https://seeinglogic.com/posts/livectf-ai-debut/">beat both human players</a> to a VM challenge from LiveCTF.
Exactly a year later, that is not surprising at all. In fact, AI has become so good at RE that it is now hard to find
challenges it cannot solve.</p>

<p>AI is only going to get better – better than most human reverse engineers. However, as this post shows, we still need
a real person to examine its results and steer it when things do not check out automagically. Plus, only a human can
appreciate the irony of a broken algorithm in the broader sense.</p>

<h2 id="references">References</h2>

<ul>
  <li><a href="/2025/03/25/default-browser-upcd.html">Inside Windows’ Default Browser Protection</a> – my earlier UCPD research</li>
  <li><a href="https://www.youtube.com/watch?v=xQUYh4iKsB0">FlyTech Videos, “Microsoft Added This Driver to Windows and Said Nothing”</a></li>
  <li><a href="https://github.com/276793422/CalcHash_CS64"><code class="language-plaintext highlighter-rouge">276793422/CalcHash_CS64</code></a> – the reference implementation that broke the case open</li>
  <li><a href="https://patents.google.com/patent/WO2000078118A2/en">US 6,570,988 B1 / WO2000078118A2</a> – the Microsoft patent</li>
  <li><a href="https://kolbi.cz/blog/2017/10/25/setuserfta-userchoice-hash-defeated-set-file-type-associations-per-user/">SetUserFTA: UserChoice hash defeated</a> – Christoph Kolbicz on the original use of the patent hash</li>
  <li><a href="https://kolbi.cz/blog/2025/07/15/ucpd-sys-userchoice-protection-driver-part-2/">UCPD.sys - UserChoice Protection Driver - Part 2</a> – Kolbicz’s follow-up research on UCPD</li>
  <li><a href="https://hitco.at/blog/windows-userchoice-protection-driver-ucpd/">https://hitco.at/blog/windows-userchoice-protection-driver-ucpd/</a></li>
  <li><a href="https://github.com/xusheng6/ucpd_analysis">https://github.com/xusheng6/ucpd_analysis</a> – all of my UCPD analysis databases and tooling</li>
  <li><a href="https://github.com/xusheng6/ucpd_analysis/tree/main/202606_DR"><code class="language-plaintext highlighter-rouge">202606_DR/</code></a> – everything from this post: the <code class="language-plaintext highlighter-rouge">.reg</code> captures, the extracted PE, the analysis databases, a standalone <code class="language-plaintext highlighter-rouge">decrypt_reg.py</code>, and the Kaitai definition</li>
</ul>]]></content><author><name>Xusheng Li</name><email>xusheng@vector35.com</email></author><category term="reversing" /><summary type="html"><![CDATA[Is Microsoft shipping a hidden binary to your computer – inside the registry? A few weeks ago I was watching a YouTube video that covered my earlier research on the UCPD driver, and for a split second I saw a registry key that I have been searching for an example of for some time. I contacted the video’s author and obtained the key from his machine. It was Base64 encoded and to my surprise, once I decoded it, it started with MZ. Sure enough, it’s a valid Windows executable sitting inside a registry key. This post is the story of both taking it apart as well as the bug I found that means the whole mechanism is dead anyway.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://binary.ninja/blog/images/ucpd-dr/pe-in-registry.png" /><media:content medium="image" url="https://binary.ninja/blog/images/ucpd-dr/pe-in-registry.png" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">A Decade (or More) in Review</title><link href="https://binary.ninja/2026/08/01/a-decade-or-more-in-review.html" rel="alternate" type="text/html" title="A Decade (or More) in Review" /><published>2026-08-01T19:00:00+00:00</published><updated>2026-08-01T19:00:00+00:00</updated><id>https://binary.ninja/2026/08/01/a-decade-or-more-in-review</id><content type="html" xml:base="https://binary.ninja/2026/08/01/a-decade-or-more-in-review.html"><![CDATA[<p>Ten years snuck up on us. It was only a few months ago that we realized how close we were to ten years of shipping
Binary Ninja to customers. It’s been an exciting journey and we’ve seen a lot of changes along the way. Our goal was
nothing short of shaking up the decompilation market. We wanted to introduce some new ideas and challenge the status quo
in how decompilation was done.</p>

<!--more-->

<h2 id="ten-thirteen-years-one-timeline"><del>Ten</del> Thirteen Years, One Timeline</h2>

<p>This post might be finishing off our ten year celebration, but when we looked at the history we had to go back even further to before we
started Vector 35! For all the details, check out out <a href="/10years/">interactive timeline</a>: every stable release, every milestone,
and the community moments that have made this journey so special.</p>

<p><a href="/10years/"><strong>Explore the timeline</strong></a></p>

<p>Let’s look at some of the highlights:</p>

<ul>
  <li><strong>Vector 35 was founded on January 14th, 2015, and Binary Ninja first went on sale July 23rd, 2016.</strong> That’s eighteen months of building before anyone could buy anything. In the meantime, we were self-funding from our work on the Cyber Grand Challenge and other contracting work.</li>
  <li><strong>Two days after we incorporated, we shipped an MMO.</strong> <a href="/10years/#community-pwnadventure-3">Pwn Adventure 3: Pwnie Island</a> ran as that year’s Ghost in the Shellcode CTF. The PwnAdventure series actually predates the company, and all of it is on the timeline in the pre-history section.</li>
  <li><strong>The community existed before the product did.</strong> Our <a href="https://slack.binary.ninja">Slack</a> went live during the beta, months before there was anything we were willing to sell. The API repository was also live and got its MIT license in April 2016, three months ahead of launch. We’ve always had a healthy plugin ecosystem as that was a goal right from the start!</li>
  <li><strong>Binary Ninja was not a decompiler for its first four years.</strong> High Level IL didn’t go a stable build until <a href="/10years/#release-2-0">2.0 in May 2020</a>. While some of our customers considered MLIL good enough for work, we always considered 2.0 the first “true decompiler”.</li>
  <li><strong>We started with, and remain committed to open source.</strong> The <a href="/10years/#community-python-prototype">original Python prototype</a>, the <a href="/10years/#community-open-source-architectures">core architectures</a>, <a href="/10years/#community-decompiler-explorer">Decompiler Explorer</a>, the <a href="https://github.com/Vector35/debugger">Debugger</a> and <a href="/10years/#community-warp">WARP</a> are all out there under open licenses, a trend we expect to continue into the future.</li>
</ul>

<p>You can also see how the rate of commits has been increasing over time! Not linear with the team-size, but we’ve been
rapidly improving the rate at which we ship featuers, even prior to the advent of semi-trustworthy AI coding.</p>

<h2 id="what-the-last-ten-days-looked-like">What the Last Ten Days Looked Like</h2>

<p>We ran <a href="/2026/07/22/10-years-of-binary-ninja.html#the-first-and-maybe-only-binary-ninja-sale">our first-ever sale</a>. A major 35% off in celebration of the last decade for the last ten days and it’s now closed. If you caught it, thank you! If you
didn’t, and you’re reading this before the <a href="https://github.com/Vector35/binaryninja-api/milestone/31">upcoming 6.0 release</a> and are interested in a commercial license or above, you should still consider buying (or renewing) now before the upcoming <a href="/2026/07/28/pricing-changes.html">price change</a>! (Non-commercial will actually see a price-decrease at the 6.0 launch)</p>

<p>We also gave something away <a href="/2026/07/22/10-years-of-binary-ninja.html#ten-days-of-giveaways">every single day</a>: shirts, bottles, mugs, stickers, a training seat, and several full licenses including an Ultimate license. Winners are listed as they confirm in the original post.</p>

<p>Because we’ve had a number of unclaimed prizes so far, once we let all the 5 business day limits pass, if we have any remaining un-allocated prizes, we’ll do a separate narrower drawing to limit the number of folks who are inelgibile or uninterested.</p>

<p>Alongside all that we published <a href="/2026/07/28/pricing-changes.html">the details behind our upcoming pricing changes</a>, and rolled out <a href="/2026/07/22/10-years-of-binary-ninja.html#a-new-look">a brand refresh</a> – new logo, more character art, and updated styling working its way across the product, the site, and the documentation. There’s even more changes to come with the website, so keep an eye on it!</p>

<h2 id="thank-you">Thank You</h2>

<p><img src="/blog/images/10years/graffiti-wall.webp" alt="The Binary Ninja crew in street clothes -- ninjas, a shiba, and a cat -- standing in front of a brick wall spray-painted with a graffiti &quot;Binary Ninja&quot; mural under the words &quot;10 Year Anniversary&quot; &gt;&lt;" class="image max-height-300" /></p>

<p>Ten years is a long time to work on one problem, and the only reason it’s been possible is the people
who bought licenses, filed bugs, wrote plugins, gave talks, argued with us in Slack about issue
priority, and generally made this a community rather than a customer base.</p>

<p>Thank you. Genuinely. We had a great ten days celebrating with you, and we’re looking forward to
finding out what the next decade’s timeline looks like.</p>

<p><a href="https://41aup4.share-na2.hsforms.com/29wZPDRsySp-r6qz2-yAhQg">Sign up for the mailing list</a> if you
want to hear about it first.</p>]]></content><author><name>Jordan Wiens</name><email>jordan@vector35.com</email></author><category term="announcements" /><category term="10years" /><summary type="html"><![CDATA[Ten years snuck up on us. It was only a few months ago that we realized how close we were to ten years of shipping Binary Ninja to customers. It’s been an exciting journey and we’ve seen a lot of changes along the way. Our goal was nothing short of shaking up the decompilation market. We wanted to introduce some new ideas and challenge the status quo in how decompilation was done.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://binary.ninja/blog/images/10years/graffiti-wall.webp" /><media:content medium="image" url="https://binary.ninja/blog/images/10years/graffiti-wall.webp" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">Pricing Changes with 6.0</title><link href="https://binary.ninja/2026/07/28/pricing-changes.html" rel="alternate" type="text/html" title="Pricing Changes with 6.0" /><published>2026-07-28T19:00:00+00:00</published><updated>2026-07-28T19:00:00+00:00</updated><id>https://binary.ninja/2026/07/28/pricing-changes</id><content type="html" xml:base="https://binary.ninja/2026/07/28/pricing-changes.html"><![CDATA[<p>When we <a href="/2026/07/22/10-years-of-binary-ninja.html">kicked off our tenth anniversary</a> a few days ago, we promised a dedicated post with specifics behind our upcoming pricing changes and the rationale behind them. This is it! Much like we’ve done <a href="/2022/10/28/3.2-released.html#price-change">previously</a>, we’ll walk through the changes and give you plenty of time beforehand.</p>

<p>The short version:</p>

<ul>
  <li>Non-Commercial is getting cheaper</li>
  <li>Commercial is going up in price</li>
  <li>Our “introductory” Ultimate pricing is ending</li>
  <li>The renewal discount is changing and rewards auto-renewal</li>
  <li>Enterprise is moving from one-size-fits-all bundles to an add-on structure</li>
  <li>Finally, yes, despite industry trends, the product will remain a perpetual license</li>
</ul>

<!--more-->

<p>The new prices will take effect when we release 6.0 (code-named Krypton). We are <em>currently</em> targeting <strong>August 19th, 2026</strong>, but the best source of truth is the public <a href="https://github.com/Vector35/binaryninja-api/milestone/31">Krypton milestone</a> on GitHub. If we make changes to the planned release date, you’ll see it there first.</p>

<p class="notification is-info">Until then, current prices remain in effect, and the <a href="/2026/07/22/10-years-of-binary-ninja.html#the-first-and-maybe-only-binary-ninja-sale">35% anniversary discount</a> (coupon <code class="language-plaintext highlighter-rouge">10YRS35OFF</code>, good through August 1st at noon ET) still stacks on top of today’s prices. If you have been thinking about buying or renewing, now is the best time!</p>

<ul>
  <li><a href="#why-were-making-these-changes">Why We’re Making These Changes</a></li>
  <li><a href="#new-license-pricing">New License Pricing</a></li>
  <li><a href="#perpetual-licensing">Perpetual Licensing</a></li>
  <li><a href="#renewals">Renewals</a></li>
  <li><a href="#enterprise-changes">Enterprise Changes</a></li>
  <li><a href="#most-savings">Most Savings</a></li>
</ul>

<h2 id="why-were-making-these-changes">Why We’re Making These Changes</h2>

<p>We don’t change our prices often, and when we do, we try to explain ourselves. Here is why we’re doing it:</p>

<ul>
  <li><strong>It’s been a long time.</strong> Non-Commercial has been $299 since 2020. Commercial was last adjusted in November 2022. This is quite a long time, especially with global prices and our operating costs rising so much over that period.</li>
  <li><strong>We are ending introductory pricing.</strong> The Ultimate edition’s price has been temporary since we introduced it while we added features. It’s got quite a few now!</li>
  <li><strong>The product is dramatically more capable.</strong> Since those prices were set, we have shipped the Ultimate edition (with Firmware Ninja and a number of additional decompilation architectures), Enterprise 2.0, <a href="https://sidekick.binary.ninja/">Sidekick</a>’s AI-assisted analysis, <a href="/2025/08/22/warp.html">WARP</a> for function matching, a fully-featured debugger with time-travel support, and a steady stream of decompiler and language improvements (Go, Swift, Rust, Objective-C, C++, and more) across our 4.x and 5.x releases and our upcoming 6.0 release will feature even more improvements. We’ll have a lot more on that topic in our <a href="/10years/">ten-year retrospective</a> later this week.</li>
  <li><strong>We are rewarding the customers who make our lives easier.</strong> Our new auto-renewal option will get the best rate going forward, and Enterprise customers who use fewer features will pay less.</li>
</ul>

<p>Raising prices lets us keep investing in the product at the pace we have been and, just as importantly, keep Binary Ninja a one-time purchase you own forever rather than a subscription you rent.</p>

<h2 id="new-license-pricing">New License Pricing</h2>

<p>A new license is a one-time purchase that includes one year of updates and support, and the license never expires. You can keep running the last version you received <em>forever</em>. Here is what a new purchase costs today versus after 6.0:</p>

<table>
  <thead>
    <tr>
      <th>Edition</th>
      <th style="text-align: right">Today</th>
      <th style="text-align: right">With 6.0</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>Free</td>
      <td style="text-align: right">$0</td>
      <td style="text-align: right">$0</td>
    </tr>
    <tr>
      <td>Non-Commercial (Named)</td>
      <td style="text-align: right">$299</td>
      <td style="text-align: right"><strong>$199</strong></td>
    </tr>
    <tr>
      <td>Commercial (Named)</td>
      <td style="text-align: right">$1,499</td>
      <td style="text-align: right"><strong>$1,799</strong></td>
    </tr>
    <tr>
      <td>Commercial (Computer)</td>
      <td style="text-align: right">$2,249</td>
      <td style="text-align: right"><strong>$2,699</strong></td>
    </tr>
    <tr>
      <td>Headless</td>
      <td style="text-align: right">$936</td>
      <td style="text-align: right"><strong>$1,259</strong></td>
    </tr>
    <tr>
      <td>Ultimate (Named)</td>
      <td style="text-align: right">$2,999</td>
      <td style="text-align: right"><strong>$3,499</strong></td>
    </tr>
    <tr>
      <td>Ultimate (Computer)</td>
      <td style="text-align: right">$4,499</td>
      <td style="text-align: right"><strong>$5,249</strong></td>
    </tr>
    <tr>
      <td>Ultimate (Floating)</td>
      <td style="text-align: right">$4,499</td>
      <td style="text-align: right"><strong>$5,499</strong></td>
    </tr>
    <tr>
      <td>  + Collaboration add-on subscription (per seat)</td>
      <td style="text-align: right">included</td>
      <td style="text-align: right"><strong>$1,299</strong></td>
    </tr>
  </tbody>
</table>

<p>A few things worth calling out:</p>

<ul>
  <li><strong>Non-Commercial’s price is going <em>down</em>, from $299 to $199.</strong> It has been $299 since we <a href="/2020/05/11/decompiler-stable-release.html">released the decompiler</a> back in 2020, and we would rather keep the hobbyist, student, and personal-use tier as accessible as possible. (The rarely-used Non-Commercial “Computer” license is being retired; Non-Commercial will be named-only going forward.)</li>
  <li><strong>The <a href="/faq/#student-discount">student discount</a> rate is unchanged at 75% off.</strong> Because it is a percentage of the base price, student pricing follows the new prices: student Non-Commercial drops from $74 to <strong>$49</strong>, while student Commercial rises from $374 to <strong>$449</strong>.</li>
  <li><strong>Ultimate’s price was always introductory.</strong> When we <a href="/2024/09/13/ultimate.html">launched Ultimate</a> in 2024 we said the $2,999 price was introductory and would rise. It took us two years, during which time we added Firmware Ninja and four more decompilation architectures (M·CORE, Hexagon, NDS32, TMS320C6x).</li>
  <li><strong>Collaboration is becoming an add-on.</strong> More on that in the <a href="#enterprise-changes">Enterprise section</a>.</li>
</ul>

<h2 id="perpetual-licensing">Perpetual Licensing</h2>

<p>Your Binary Ninja license does not expire. Renewing extends access to updates and support for an additional year but it is not required to use versions you’ve had access to.</p>

<p>As commercial software has increasingly moved toward subscriptions, we considered whether we should too. The advantage is a more consistent funding model, but we didn’t feel it was right for us.</p>

<p>Instead, with 6.0, we are reducing our renewal discounts. This does increase the price of renewals, but they remain discounted from the cost of a new license and unlike a subscription, the software does not expire.</p>

<p>We believe this strikes the right balance: your renewal supports continued development, while you retain a perpetual license and are never forced to keep paying merely to continue using the tool you’ve already paid for.</p>

<h2 id="renewals">Renewals</h2>

<p>With 6.0 we are changing renewals in two ways: The discount is changing, and <strong>the new auto-renewal option is now cheaper than manual renewal.</strong></p>

<table>
  <thead>
    <tr>
      <th>Edition</th>
      <th style="text-align: right">Old renewal</th>
      <th style="text-align: right">New auto-renewal</th>
      <th style="text-align: right">New manual renewal</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>Non-Commercial</td>
      <td style="text-align: right">$149</td>
      <td style="text-align: right"><strong>$139</strong></td>
      <td style="text-align: right"><strong>$159</strong></td>
    </tr>
    <tr>
      <td>Commercial (Named)</td>
      <td style="text-align: right">$749</td>
      <td style="text-align: right"><strong>$1,259</strong></td>
      <td style="text-align: right"><strong>$1,439</strong></td>
    </tr>
    <tr>
      <td>Commercial (Computer)</td>
      <td style="text-align: right">$1,124</td>
      <td style="text-align: right"><strong>$1,889</strong></td>
      <td style="text-align: right"><strong>$2,159</strong></td>
    </tr>
    <tr>
      <td>Headless</td>
      <td style="text-align: right">$468</td>
      <td style="text-align: right"><strong>$881</strong></td>
      <td style="text-align: right"><strong>$1,007</strong></td>
    </tr>
    <tr>
      <td>Ultimate (Named)</td>
      <td style="text-align: right">$1,829</td>
      <td style="text-align: right"><strong>$2,799</strong></td>
      <td style="text-align: right"><strong>$3,149</strong></td>
    </tr>
    <tr>
      <td>Ultimate (Computer)</td>
      <td style="text-align: right">$2,744</td>
      <td style="text-align: right"><strong>$4,199</strong></td>
      <td style="text-align: right"><strong>$4,724</strong></td>
    </tr>
    <tr>
      <td>Ultimate (Floating)</td>
      <td style="text-align: right">$2,744</td>
      <td style="text-align: right"><strong>$4,399</strong></td>
      <td style="text-align: right"><strong>$4,949</strong></td>
    </tr>
    <tr>
      <td>Collaboration Add-On</td>
      <td style="text-align: right">Bundled</td>
      <td style="text-align: right"><strong>$1,299</strong></td>
      <td style="text-align: right"><strong>$1,299</strong></td>
    </tr>
  </tbody>
</table>

<p>We want to be upfront about this: for Commercial and Ultimate, renewals are going up meaningfully. There are two reasons behind the change. First, the old renewal was set many years and features ago, and ongoing development, which is what support renewals pay for, has accelerated enormously in that time. Second, auto-renewal makes life easier for both us and customers who want to keep getting the latest versions and we want to reward them. In fact, Non-Commercial’s new renewal rate is now <em>cheaper</em> if you set up auto-renewal.</p>

<h2 id="enterprise-changes">Enterprise Changes</h2>

<p>The biggest structural change is to how we sell Enterprise and collaboration features. While it might initially raise costs for Enterprise customers, in the long-run it will let organizations pay for only what they need.</p>

<p>Collaboration itself was always a subscription (client licenses continued to function after support ended but collaboration did not), and that is not changing.</p>

<p>Until now, every Enterprise deployment started with a server bundle. The bundle included a minimum purchase of a licensed server plus three floating Ultimate seats, regardless of which features you actually needed. With 6.0, we are no longer pricing the server separately and are moving toward an à la carte model:</p>

<ul>
  <li><strong>There is no minimum bundling.</strong> You buy the Ultimate licenses you need – named, computer, or floating – and nothing else is required.</li>
  <li><strong>Collaboration is a per-seat add-on ($1,299).</strong> The versioned, shared project database with real-time chat that used to define Enterprise is now something you add only to the seats that need it.</li>
  <li><strong>Servers are no longer licensed individually.</strong> You can decide how many self-hosted Enterprise servers to split your floating licenses between. This is especially useful for customers with multiple segregated networks.</li>
</ul>

<p>The trade-off should be clear: a large team that uses <em>everything</em> Enterprise offers will pay more than before, but a team that only needs a subset can spend less. Some concrete examples for three seats:</p>

<table>
  <thead>
    <tr>
      <th>Configuration (3 seats)</th>
      <th style="text-align: right">Old bundle</th>
      <th style="text-align: right">With 6.0</th>
      <th style="text-align: center">Change</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>Floating + Collaboration</td>
      <td style="text-align: right">$19,794</td>
      <td style="text-align: right">$20,394</td>
      <td style="text-align: center">~even</td>
    </tr>
    <tr>
      <td>Floating, no Collaboration</td>
      <td style="text-align: right">$19,794</td>
      <td style="text-align: right">$16,497</td>
      <td style="text-align: center"><strong>−17%</strong></td>
    </tr>
    <tr>
      <td>Named + Collaboration</td>
      <td style="text-align: right">$19,794</td>
      <td style="text-align: right">$14,394</td>
      <td style="text-align: center"><strong>−27%</strong></td>
    </tr>
  </tbody>
</table>

<p>The customers that will see increases are the largest deployments that use every feature at scale. If you run a large Enterprise deployment and want to walk through what the new model means for your specific configuration, please <a href="mailto:enterprise@vector35.com">reach out</a> and we will work with you before your next renewal.</p>

<h2 id="most-savings">Most Savings</h2>

<p>So how can you get the most savings possible?</p>

<ul>
  <li><strong>Buy at current prices, with 35% off on top.</strong> Our 10-year anniversary coupon, <code class="language-plaintext highlighter-rouge">10YRS35OFF</code>, is good through <strong>August 1st at noon ET</strong> and stacks on top of today’s pricing for <a href="/purchase/">Non-Commercial, Commercial, and Ultimate</a>.</li>
  <li><strong>Renew early to lock in current renewal pricing.</strong> As long as you have less than a year of support remaining, you can <a href="/renew/">renew now</a> at today’s rate. If you want to renew multiple years in advance, that’s fine too! Just wait until after August 1st when the coupon ends and the renewal system will be back to allowing early-renewal. You can purchase multiple times and extend your support out at the current price.</li>
  <li><strong>Existing customers keep their current support.</strong> Changing prices never affects updates you have already paid for. If your support is active, you continue to receive updates at no additional charge until it lapses. If you don’t renew, you’ll still have access to all of your databases and be able to use existing versions though of course we’re sad to see you go.</li>
</ul>

<p>As always, if you have questions about how any of this applies to your situation, our <a href="/support/">support</a> team and the community <a href="https://slack.binary.ninja/">Slack</a> are the best places to reach us. Thanks, as ever, for ten years of trust – we do not take pricing decisions, or your support, lightly.</p>]]></content><author><name>Jordan Wiens</name><email>jordan@vector35.com</email></author><category term="announcements" /><category term="10years" /><summary type="html"><![CDATA[When we kicked off our tenth anniversary a few days ago, we promised a dedicated post with specifics behind our upcoming pricing changes and the rationale behind them. This is it! Much like we’ve done previously, we’ll walk through the changes and give you plenty of time beforehand. The short version: Non-Commercial is getting cheaper Commercial is going up in price Our “introductory” Ultimate pricing is ending The renewal discount is changing and rewards auto-renewal Enterprise is moving from one-size-fits-all bundles to an add-on structure Finally, yes, despite industry trends, the product will remain a perpetual license]]></summary></entry><entry><title type="html">10 Years of Binary Ninja</title><link href="https://binary.ninja/2026/07/22/10-years-of-binary-ninja.html" rel="alternate" type="text/html" title="10 Years of Binary Ninja" /><published>2026-07-22T16:00:00+00:00</published><updated>2026-07-22T16:00:00+00:00</updated><id>https://binary.ninja/2026/07/22/10-years-of-binary-ninja</id><content type="html" xml:base="https://binary.ninja/2026/07/22/10-years-of-binary-ninja.html"><![CDATA[<div class="notification is-warning is-light" role="status">
<b>Update:</b> The anniversary sale has ended. The <code>10YRS35OFF</code> coupon expired on August 1st, 2026 at noon ET and is no longer valid, and the ten days of giveaways are complete. The rest of this post is preserved as originally published. See <a href="/10years/">all of our tenth anniversary posts</a>.
</div>

<p><img src="/blog/images/10years/10-year-anniversary.jpg" alt="Ten years of Binjas! &gt;" class="image max-height-400" /></p>

<p>Ten years ago tomorrow, we shipped the first build of Binary Ninja. In the beginning, there were just four of us looking to take on the monumental task of building a commercial-grade decompiler from scratch. We knew it would be a lot of work, but we were excited to take our ideas about how we could improve the state of the art and make a difference in a community we had long been involved in. A decade later and we’ve had tens of thousands of customers put their trust in us. Other than the name and having a dark theme, the product feels light-years different from the version we first launched with. And the most surprising thing of all? The amazing community that has grown around the tool. The super active plugin ecosystem, Slack, people posting tips on YouTube, and all the amazing feedback we’ve been given over the years have truly blown us away.</p>

<p>Given all that, we’re going to celebrate it in style. Over the next ten days we’re running <strong><a href="/2026/07/22/10-years-of-binary-ninja.html#ten-days-of-giveaways">10 Days for 10 Years</a></strong>: our <a href="/2026/07/22/10-years-of-binary-ninja.html#the-first-and-maybe-only-binary-ninja-sale">first-ever sale</a>, a <a href="/2026/07/22/10-years-of-binary-ninja.html#ten-days-of-giveaways">giveaway every single day</a>, and more blog posts covering <a href="/2026/07/22/10-years-of-binary-ninja.html#what-else-is-coming">where we came from, where 6.0 is going</a>, and <a href="/2026/07/22/10-years-of-binary-ninja.html#a-new-look">a fresh new facelift</a> for the brand.</p>

<!--more-->

<ul>
  <li><a href="/2026/07/22/10-years-of-binary-ninja.html#the-first-and-maybe-only-binary-ninja-sale">The First (and Maybe Only) Binary Ninja Sale</a></li>
  <li><a href="/2026/07/22/10-years-of-binary-ninja.html#ten-days-of-giveaways">Ten Days of Giveaways</a></li>
  <li><a href="/2026/07/22/10-years-of-binary-ninja.html#what-else-is-coming">What Else Is Coming</a></li>
  <li><a href="/2026/07/22/10-years-of-binary-ninja.html#a-new-look">A New Look</a></li>
  <li><a href="/2026/07/22/10-years-of-binary-ninja.html#thank-you">Thank You</a></li>
</ul>

<h2 id="the-first-and-maybe-only-binary-ninja-sale">The First (and Maybe Only) Binary Ninja Sale</h2>

<p>In ten years we have never put Binary Ninja on sale. Not on Black Friday, not at conferences, not for any other occasion. We’ve offered “welcome back” discounts for former customers, and we’ve offered our <a href="/faq/#student-discount">student discount</a> and sometimes we’d give away shirts or other items, but that’s it. Our pricing has always been firm so people knew that the best time to buy was always <em>now</em>.</p>

<p>We’re making an exception for the next ten days.</p>

<div class="notification is-info is-light" role="status">
<s><b>From now through August 1st at noon ET, use coupon code <code>10YRS35OFF</code> at checkout for 35% off.</b></s> <span class="small"><b>Expired</b> — this coupon is no longer valid.</span>
</div>

<p>Yes, that’s 35% off, and given that <a href="/2026/07/22/10-years-of-binary-ninja.html#what-else-is-coming">prices are changing with 6.0</a>, this is the lowest price Binary Ninja will ever be for most editions, by a large margin. Maybe we’ll do this again in 10 more years, but don’t be surprised if we wait 35 years instead! <a href="https://vector35.com/">Thirty-five</a> is, of course, our favorite number!</p>

<p>There are a few things to note about the coupon code. First, no exceptions. If you miss this time window, that’s unfortunate, but we will not be extending the time window. Payment must be received before the coupon expires or it will not be valid. Second, the code is valid for all editions of Binary Ninja you can purchase automatically online. This includes Ultimate, Commercial, and Non-Commercial. Third, current customers can take advantage of this discount too! As long as you have less than one year of support left on your license, you can renew early and add another year at the discounted rate. Finally, it can’t be stacked with our two other discounts – the <a href="/faq/#student-discount">student discount</a> and the welcome back discount.</p>

<p>We’re so happy we’ve been able to thrive and grow over the past decade and this is a small way we can say thank-you.</p>

<p><a href="/purchase/"><strong>Buy Binary Ninja →</strong></a></p>

<h2 id="ten-days-of-giveaways">Ten Days of Giveaways</h2>

<p><img src="/blog/images/10years/claw-machine.webp" alt="Free Stuff! Team Binjy playing a claw machine for binja stress balls &gt;" class="image max-height-200" /></p>

<p>Every day for the next ten days we’re giving something away. Giveaways include our awesome <a href="https://shop.binary.ninja/">branded items</a>, a <a href="/training/">training seat</a>, and even several full licenses.</p>

<p>No purchase is necessary to enter or win, and the only requirement is being on our mailing list. The full <a href="https://docs.google.com/document/d/1lICcGUOCyIFjfX2v3xrVEbPqLOLKkonTdGV4Xg5v3EQ/edit?usp=sharing">Terms and Conditions</a> have all the details, including how winners are picked and notified, and the handful of regions we unfortunately can’t include because of local sweepstakes laws.</p>

<p>We’ll come back and fill in the Winners column below as we go – each day’s drawing is run through <a href="https://www.random.org/">random.org</a>, and we’ll list the winners here in anonymized form.</p>

<table>
  <thead>
    <tr>
      <th>Date</th>
      <th>Prize</th>
      <th>Count</th>
      <th>Winners</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>July 23rd</td>
      <td><a href="/purchase/">Non-Commercial license</a></td>
      <td>1</td>
      <td><em>Backup notified</em></td>
    </tr>
    <tr>
      <td>July 24th</td>
      <td><a href="https://shop.binary.ninja/products/extra-soft-tee-shirt">Extra Soft Tee Shirt</a></td>
      <td>3</td>
      <td><em>dragonbaby, anonymous, Backup notified</em></td>
    </tr>
    <tr>
      <td>July 25th</td>
      <td><a href="https://shop.binary.ninja/products/journey-binary-ninja-bottle">Journey Bottle</a></td>
      <td>3</td>
      <td><em>@thinety</em>, <em>Backups notified</em></td>
    </tr>
    <tr>
      <td>July 26th</td>
      <td><a href="/training/">Introduction to Binary Ninja</a> training seat</td>
      <td>1</td>
      <td><em>Backups notified</em></td>
    </tr>
    <tr>
      <td>July 27th</td>
      <td><a href="https://shop.binary.ninja/products/14oz-binary-ninja-coffee-mug">Coffee Mug</a></td>
      <td>3</td>
      <td><em>Winners notified</em></td>
    </tr>
    <tr>
      <td>July 28th</td>
      <td><a href="/purchase/">Non-Commercial license</a> + <a href="https://sidekick.binary.ninja">Sidekick</a></td>
      <td>1</td>
      <td><em>@hyprdude</em></td>
    </tr>
    <tr>
      <td>July 29th</td>
      <td><a href="/purchase/">Commercial license</a></td>
      <td>1</td>
      <td><em>Winner notified</em></td>
    </tr>
    <tr>
      <td>July 30th</td>
      <td><a href="https://shop.binary.ninja/products/stickers-10-pack">Stickers (10 pack)</a></td>
      <td>10</td>
      <td><em>anonymous</em>, <em>winterknife</em>, <em>other winners notified</em></td>
    </tr>
    <tr>
      <td>July 31st</td>
      <td><a href="https://shop.binary.ninja/products/ninja-disguise">Ninja Disguise</a> / <a href="https://shop.binary.ninja/products/soft-enamel-pins-2-pack">Enamel Pins</a> / <a href="https://shop.binary.ninja/products/ninja-diary">Ninja Diary</a></td>
      <td>3</td>
      <td><em>David B, Other winners notified</em></td>
    </tr>
    <tr>
      <td>August 1st</td>
      <td><a href="/purchase/"><strong>Ultimate license</strong></a></td>
      <td>1</td>
      <td><em>h4mst3r accepted</em></td>
    </tr>
  </tbody>
</table>

<p class="notification is-info"><strong>You must be subscribed to our mailing list to be eligible.</strong> Winners are drawn from the subscriber list each day and notified by email. <a href="https://41aup4.share-na2.hsforms.com/29wZPDRsySp-r6qz2-yAhQg">Sign up here</a> – it takes about ten seconds, and it’s also where you can hear about all the latest updates. Don’t worry, it’s a very low-volume list!</p>

<p>There are no hoops to jump through. Subscribe, and you’re in for every remaining drawing. If you’re already on the list, you’re already eligible and you don’t need to do anything.</p>

<h2 id="what-else-is-coming">What Else Is Coming</h2>

<p>The sale and the giveaways are just the start. We’re publishing several blog posts over the next week looking both backward and forward.</p>

<div class="team-swap">
	<img src="/blog/images/10years/team.jpg" alt="The four of us outside the office, back near the beginning" />
	<img class="team-swap-alt" src="/blog/images/10years/team-sword.jpg" alt="The same four of us, now armed" />
</div>

<style>
/* Tables shrink-to-fit rather than filling the column, so the giveaway table is
   narrow enough to sit beside the floated claw image. Clearing drops it below
   instead, so the image floats against the intro paragraphs and the table gets
   its own full-width row. */
.post-entry table {
	clear: both;
}

/* The global .juxtapose rule stretches sliders to the full column width, which
   suits wide screenshots but not this near-square logo lockup -- stretched that
   wide, the two logos sit side by side and the wipe never crosses the artwork.
   Cap it so the slider is about as wide as the lockup itself. */
.post-entry .juxtapose.juxtapose-lockup {
	width: 420px !important;
	max-width: 100%;
	margin-left: auto;
	margin-right: auto;
}

/* Easter egg: hover the team photo to arm everyone. Both images are the same
   dimensions so the swap registers exactly. Gated on (hover: hover) so touch
   devices just get the straight photo rather than a stuck-on overlay. */
.team-swap {
	position: relative;
	float: right;
	width: 260px;
	max-width: 100%;
	margin: 0 0 23px 30px;
}
.team-swap img {
	display: block;
	width: 100%;
	height: auto;
}
.team-swap .team-swap-alt {
	position: absolute;
	inset: 0;
	opacity: 0;
	z-index: 2;
	transition: opacity 0.25s ease-in-out;
}
@media (hover: hover) {
	.team-swap:hover .team-swap-alt {
		opacity: 1;
	}
}
@media (prefers-reduced-motion: reduce) {
	.team-swap .team-swap-alt {
		transition: none;
	}
}
/* Match the site convention: floated images un-float and center on mobile. */
@media (max-width: 768px) {
	.team-swap {
		float: none;
		margin: 0 auto 23px;
	}
}
</style>

<ul>
  <li><strong>A Look Back</strong> – a proper retrospective on how Binary Ninja got here: the decisions that worked, the ones that didn’t, what the product looked like before it had a decompiler, and a few stories you probably haven’t heard. If you’ve only known Binary Ninja since it got good, feel free to come back and see the before-times when that wasn’t the case!</li>
  <li><strong>The Road to 6.0</strong> – we’re going to walk through what’s landing in 6.0, code-named Krypton. We’ll also have our usual <a href="https://www.youtube.com/@vector35/live">feature stream</a>. Of course, the hardcore fans already know you don’t have to wait for us since the <a href="https://github.com/Vector35/binaryninja-api/milestone/31">Krypton milestone</a> on GitHub is public.</li>
  <li><strong>Pricing Changes</strong> – Binary Ninja prices are changing when we release 6.0, going up for most editions. We’ll publish a dedicated post in the next week with the specific numbers and, more importantly, the reasoning: the changes since we last updated prices, how long it’s been, and what’s happened in that time period.</li>
</ul>

<p>We’re telling you before it happens rather than after, and the <a href="/2026/07/22/10-years-of-binary-ninja.html#the-first-and-maybe-only-binary-ninja-sale">35% off</a> is live now, which means anyone who wants to buy (or renew!) has ten days to do it.</p>

<h2 id="a-new-look">A New Look</h2>

<p>Another way we wanted to celebrate the last decade was to make some branding changes. We love both our original logo and our whole mascot team. But if we’re honest, we haven’t always been consistent with the logo, colors, and styling so we took the opportunity to not only do a website refresh but to standardize across the product, social media, and websites. There are mostly small changes, but we love that they take what’s good and make it even better.</p>

<div class="juxtapose juxtapose-lockup max-height-400" style="margin-bottom: 1rem;">
  <img data-label="Before" src="/blog/images/10years/lockup-before-light.png" />
  <img data-label="After" src="/blog/images/10years/lockup-after-light.png" />
</div>

<p>This brand refresh includes a new logo, a growing cast of character art, and updated styling rolling out across the website, social media, and documentation. The documentation is currently on a test branch if you want a <a href="https://github.com/Vector35/binaryninja-api/tree/zensical">sneak peek</a>. Come check it later, but if you haven’t seen the documentation in a while you might already be surprised at how much it’s changed!</p>

<ul>
  <li><a href="https://dev-docs.binary.ninja/">User Documentation</a> – the user guide, from getting started through the deeper analysis features</li>
  <li><a href="https://dev-api.binary.ninja/">Python API Reference</a> – the full Python API</li>
  <li><a href="https://dev-rust.binary.ninja/">Rust API Reference</a> – the Rust API</li>
</ul>

<h2 id="team-binjy">Team Binjy</h2>

<p>We wanted to give a special thanks to <a href="https://www.deviantart.com/irkurniadi">the artist</a> behind all of our awesome Team Binjy artwork! If you’ve enjoyed all the cool graphics that accompany our stable releases, you have them to thank!</p>

<p><a href="/blog/images/10years/team-binjy.jpg"><img src="/blog/images/10years/team-binjy.jpg" alt="The whole crew, on the move &gt;&lt;" class="image max-height-400" /></a></p>

<h2 id="thank-you">Thank You</h2>

<p>We started Vector 35 almost twelve years ago now, and we’ve spent the vast majority of that time focused on one hard problem. We’ve only been able to do it because of the community. To all of you for buying licenses, filing bugs, spreading <a href="/love/">the love</a>, writing plugins, giving talks, and joining our Slack to point out why your favorite GitHub issue should be prioritized higher than we thought…</p>

<p>Thank you! You’ve made this better than we could have ever expected and we’ve loved every minute. We’re looking forward to the next decade, and hope you are too.</p>

<p>We also wanted to send a special thank-you to our longest running customer. Sierra Haex purchased a license the second day we were on-sale and has maintained a license since then! We’ve sent her a special thank-you package and extended her license for another 10 years for free! Thanks for your loyalty and support! ❤️</p>

<p><strong>Don’t miss the rest of it:</strong> the daily giveaways, the retrospective, the 6.0 preview, and the pricing details all go out to the mailing list first. <a href="https://41aup4.share-na2.hsforms.com/29wZPDRsySp-r6qz2-yAhQg">Subscribe here</a>.</p>]]></content><author><name>Jordan Wiens</name><email>jordan@vector35.com</email></author><category term="announcements" /><category term="10years" /><summary type="html"><![CDATA[Update: The anniversary sale has ended. The 10YRS35OFF coupon expired on August 1st, 2026 at noon ET and is no longer valid, and the ten days of giveaways are complete. The rest of this post is preserved as originally published. See all of our tenth anniversary posts. Ten years ago tomorrow, we shipped the first build of Binary Ninja. In the beginning, there were just four of us looking to take on the monumental task of building a commercial-grade decompiler from scratch. We knew it would be a lot of work, but we were excited to take our ideas about how we could improve the state of the art and make a difference in a community we had long been involved in. A decade later and we’ve had tens of thousands of customers put their trust in us. Other than the name and having a dark theme, the product feels light-years different from the version we first launched with. And the most surprising thing of all? The amazing community that has grown around the tool. The super active plugin ecosystem, Slack, people posting tips on YouTube, and all the amazing feedback we’ve been given over the years have truly blown us away. Given all that, we’re going to celebrate it in style. Over the next ten days we’re running 10 Days for 10 Years: our first-ever sale, a giveaway every single day, and more blog posts covering where we came from, where 6.0 is going, and a fresh new facelift for the brand.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://binary.ninja/blog/images/10years/10-year-anniversary.jpg" /><media:content medium="image" url="https://binary.ninja/blog/images/10years/10-year-anniversary.jpg" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">5.3 Release 2</title><link href="https://binary.ninja/2026/06/09/5.3-release-2.html" rel="alternate" type="text/html" title="5.3 Release 2" /><published>2026-06-09T13:33:07+00:00</published><updated>2026-06-09T13:33:07+00:00</updated><id>https://binary.ninja/2026/06/09/5.3-release-2</id><content type="html" xml:base="https://binary.ninja/2026/06/09/5.3-release-2.html"><![CDATA[<p><img src="/blog/images/5.3-release/jotunheim.jpg" alt="Binjas, assemble! &gt;" class="image max-height-300" /></p>

<p>Today we’re releasing a new “R2” for <a href="https://binary.ninja/2026/04/13/binary-ninja-5.3-jotunheim.html">Jotunheim</a>. This second stable release of 5.3 primarily contains stability fixes with a heavy emphasis on crashes and hangs (in part thanks to our new <a href="https://binary.ninja/2026/04/13/binary-ninja-5.3-jotunheim.html#crash-reporting">Sentry</a> infrastructure). This release should result in a much more stable reverse engineering experience.</p>

<p>As always, customers with <a href="https://binary.ninja/purchase/">active support</a> on the <a href="https://docs.binary.ninja/guide/index.html#development-branch">development branch</a> have access to these changes and more.</p>

<!--more-->

<h2 id="binaryview-fixes">BinaryView Fixes</h2>

<ul>
  <li>Multiple fixes for crashes loading malformed Mach-O binaries and binaries with malformed Objective-C metadata</li>
  <li>Fixed a hang when loading an ELF MIPS binary containing a corrupt symbol table</li>
  <li>Fixed long analysis stalls on malformed size claims in C++ RTTI data</li>
  <li>Fixed malformed PE exception directory causing large allocations / hangs</li>
  <li>Fixed a memory leak from VxWorks view loading (Ultimate only) (<a href="https://github.com/Vector35/binaryninja-api/issues/8075">#8075</a>)</li>
</ul>

<h2 id="analysis-and-architectures">Analysis and Architectures</h2>

<ul>
  <li>Multiple Thumb-2 lifting fixes including an out-of-bounds read during lifting, and incorrect handling of IT (conditional) instructions</li>
  <li>Fixed an out-of-bounds read when lifting certain Rust binaries (<a href="https://github.com/Vector35/binaryninja-api/issues/8155">#8155</a>)</li>
  <li>Fixed a crash from unbounded recursion when two functions that call each other are both marked “inline during analysis”</li>
  <li>Fixed crashes when no default calling convention is registered for a platform (resulted in both PDB and WARP crashes) (<a href="https://github.com/Vector35/binaryninja-api/issues/8196">#8196</a>, <a href="https://github.com/Vector35/binaryninja-api/issues/8181">#8181</a>)</li>
</ul>

<h2 id="stability-races-and-lifetimes">Stability: Races and Lifetimes</h2>

<ul>
  <li>Multiple fixes for crashes when a binary view is closed or removed while still in use</li>
  <li>Fixed a race condition on Windows x64 binaries during view initialization</li>
  <li>Fixed a WARP crash when its sidebar was deleted just as analysis completed</li>
</ul>

<h2 id="ui-and-platform">UI and Platform</h2>

<ul>
  <li>Fixed a crash rendering very long symbol names when the maximum symbol width setting is smaller than the symbol being truncated</li>
  <li>Fixed an abort when checking file paths the OS denies access to (e.g. permission errors while reading the keybindings file)</li>
  <li>Fixed a UI crash when a structure’s base type or a member type can’t be resolved from a named type reference</li>
  <li>Fixed keybindings not saving in the free version on macOS (<a href="https://github.com/Vector35/binaryninja-api/issues/7253">#7253</a>)</li>
</ul>

<h2 id="debugger">Debugger</h2>

<p>The debugger received its own batch of 20 stabilization commits in this release. Apologies to those impacted by these issues:</p>

<ul>
  <li>Multiple crash fixes in debug adapters when a connection is unavailable or drops mid-operation (<a href="https://github.com/Vector35/debugger/issues/1073">#1073</a>, <a href="https://github.com/Vector35/debugger/issues/1076">#1076</a>, <a href="https://github.com/Vector35/debugger/issues/1077">#1077</a>, <a href="https://github.com/Vector35/debugger/issues/1078">#1078</a>)</li>
  <li>Multiple object-lifetime and threading fixes (<a href="https://github.com/Vector35/debugger/issues/1047">#1047</a>, <a href="https://github.com/Vector35/debugger/issues/1048">#1048</a>, <a href="https://github.com/Vector35/debugger/issues/1058">#1058</a>, <a href="https://github.com/Vector35/debugger/issues/1062">#1062</a>, <a href="https://github.com/Vector35/debugger/issues/1080">#1080</a>, <a href="https://github.com/Vector35/debugger/issues/1086">#1086</a>)</li>
  <li>Fixed a deadlock and repeated resume-event spam with conditional breakpoints (<a href="https://github.com/Vector35/debugger/issues/1051">#1051</a>)</li>
  <li>Fixed the native Windows adapter being unusable after detaching from a target (<a href="https://github.com/Vector35/debugger/issues/1050">#1050</a>)</li>
  <li>Multiple error-handling improvements so failures while reading debuggee memory or communicating with remote targets are logged instead of crashing or being silently dropped (<a href="https://github.com/Vector35/debugger/issues/1046">#1046</a>, <a href="https://github.com/Vector35/debugger/issues/1079">#1079</a>, <a href="https://github.com/Vector35/debugger/issues/1081">#1081</a>)</li>
  <li>UI fixes: time-travel debugging widgets no longer appear for targets that don’t support it, and the debugger sidebar no longer steals focus every time the target stops (<a href="https://github.com/Vector35/debugger/issues/1033">#1033</a>, <a href="https://github.com/Vector35/debugger/issues/1055">#1055</a>)</li>
</ul>

<p>These builds are now live on both our website and update servers. If you’re a Binary Ninja Free user, you can download a
new installer <a href="https://binary.ninja/free">here</a>. If you’re a Personal, Commercial, or Enterprise user, the new build is
available from the <a href="https://portal.binary.ninja/">portal</a> or via a <a href="https://binary.ninja/recover">license recovery
email</a>. And as always, you can
<a href="https://docs.binary.ninja/guide/index.html#updates">update</a> your existing client.</p>]]></content><author><name>Jordan Wiens</name><email>jordan@vector35.com</email></author><category term="announcements" /><category term="stable" /><category term="debugger" /><summary type="html"><![CDATA[Today we’re releasing a new “R2” for Jotunheim. This second stable release of 5.3 primarily contains stability fixes with a heavy emphasis on crashes and hangs (in part thanks to our new Sentry infrastructure). This release should result in a much more stable reverse engineering experience. As always, customers with active support on the development branch have access to these changes and more.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://binary.ninja/blog/images/5.3-release/jotunheim.jpg" /><media:content medium="image" url="https://binary.ninja/blog/images/5.3-release/jotunheim.jpg" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">Binary Ninja 5.3 (Jotunheim)</title><link href="https://binary.ninja/2026/04/13/binary-ninja-5.3-jotunheim.html" rel="alternate" type="text/html" title="Binary Ninja 5.3 (Jotunheim)" /><published>2026-04-13T13:33:07+00:00</published><updated>2026-04-13T13:33:07+00:00</updated><id>https://binary.ninja/2026/04/13/binary-ninja-5.3-jotunheim</id><content type="html" xml:base="https://binary.ninja/2026/04/13/binary-ninja-5.3-jotunheim.html"><![CDATA[<p><img src="/blog/images/5.3-release/jotunheim.jpg" alt="Binjas, assemble! This release is code-named Jotunheim in honor of Norse mythology though of course the modern Marvel re-telling is perhaps the most well-known. &gt;" class="image max-height-300" /></p>

<p>For Binary Ninja 5.3, we’re bringing features and fixes across a number of areas. For improved interoperability, we’ve added <a href="/2026/04/13/binary-ninja-5.3-jotunheim.html#ghidra-export">Ghidra Export</a> to the existing <a href="/2025/11/13/binary-ninja-5.2-io.html#ghidra-import">Ghidra Import</a> code and have improved our <a href="/2026/04/13/binary-ninja-5.3-jotunheim.html#idb-import-improvements">IDB Import</a> capability. For new architectures and platforms, we’ve added <a href="/2026/04/13/binary-ninja-5.3-jotunheim.html#nds32">NDS32</a> to Ultimate, a new <a href="/2026/04/13/binary-ninja-5.3-jotunheim.html#aarch64-ilp32-abi">ILP32 ABI</a> for AArch64, and a new set of APIs for <a href="/2026/04/13/binary-ninja-5.3-jotunheim.html#new-architecture-apis">“weird” architectures</a>. And of course, we’ve made a number of improvements to the UI including a new <a href="/2026/04/13/binary-ninja-5.3-jotunheim.html#mach-o-architecture-picker">Universal Mach-O loader UI</a>, usability improvements to the <a href="/2026/04/13/binary-ninja-5.3-jotunheim.html#container-browser-improvements">container browser</a>, and a new <a href="/2026/04/13/binary-ninja-5.3-jotunheim.html#command-palette-refresh">“super” command palette</a>! Plus, changes to the <a href="/2026/04/13/binary-ninja-5.3-jotunheim.html#debugger">debugger</a>, <a href="/2026/04/13/binary-ninja-5.3-jotunheim.html#enterprise">enterprise features</a>, new opt-in <a href="/2026/04/13/binary-ninja-5.3-jotunheim.html#crash-reporting">crash reporting</a> to help us squash bugs faster, and so much more!</p>

<div class="notification is-info is-light" role="status">
<b>Note:</b> A <a href="/2026/06/09/5.3-release-2.html">second release (R2)</a> with stability improvements and bug fixes is now available.
</div>

<!--more-->

<ul>
  <li><a href="/2026/04/13/binary-ninja-5.3-jotunheim.html#architecture--platform">Architecture / Platform</a>
    <ul>
      <li><a href="/2026/04/13/binary-ninja-5.3-jotunheim.html#new-architecture-apis">New Architecture APIs</a></li>
      <li><a href="/2026/04/13/binary-ninja-5.3-jotunheim.html#nds32">NDS32</a></li>
      <li><a href="/2026/04/13/binary-ninja-5.3-jotunheim.html#aarch64-ilp32-abi">AArch64 ILP32 ABI</a></li>
    </ul>
  </li>
  <li><a href="/2026/04/13/binary-ninja-5.3-jotunheim.html#ui">UI</a>
    <ul>
      <li><a href="/2026/04/13/binary-ninja-5.3-jotunheim.html#mach-o-architecture-picker">Mach-O Architecture Picker</a></li>
      <li><a href="/2026/04/13/binary-ninja-5.3-jotunheim.html#container-browser-improvements">Container Browser Improvements</a></li>
      <li><a href="/2026/04/13/binary-ninja-5.3-jotunheim.html#command-palette-refresh">Command Palette Refresh</a></li>
    </ul>
  </li>
  <li><a href="/2026/04/13/binary-ninja-5.3-jotunheim.html#types--signatures">Types &amp; Signatures</a>
    <ul>
      <li><a href="/2026/04/13/binary-ninja-5.3-jotunheim.html#type-library-utilities">Type Library Utilities</a></li>
      <li><a href="/2026/04/13/binary-ninja-5.3-jotunheim.html#warp-improvements">WARP Improvements</a></li>
    </ul>
  </li>
  <li><a href="/2026/04/13/binary-ninja-5.3-jotunheim.html#interoperability">Interoperability</a>
    <ul>
      <li><a href="/2026/04/13/binary-ninja-5.3-jotunheim.html#ghidra-export">Ghidra Export</a></li>
      <li><a href="/2026/04/13/binary-ninja-5.3-jotunheim.html#idb-import-improvements">IDB Import Improvements</a></li>
    </ul>
  </li>
  <li><a href="/2026/04/13/binary-ninja-5.3-jotunheim.html#enterprise">Enterprise</a></li>
  <li><a href="/2026/04/13/binary-ninja-5.3-jotunheim.html#debugger">Debugger</a>
    <ul>
      <li><a href="/2026/04/13/binary-ninja-5.3-jotunheim.html#hardware-and-conditional-breakpoints">Hardware and Conditional Breakpoints</a></li>
      <li><a href="/2026/04/13/binary-ninja-5.3-jotunheim.html#new-debug-adapters">New Debug Adapters</a></li>
    </ul>
  </li>
  <li><a href="/2026/04/13/binary-ninja-5.3-jotunheim.html#crash-reporting">Crash Reporting</a></li>
  <li><a href="/2026/04/13/binary-ninja-5.3-jotunheim.html#open-source-contributions">Open-Source Contributions</a></li>
  <li><a href="/2026/04/13/binary-ninja-5.3-jotunheim.html#everything-else">Everything Else</a></li>
</ul>

<h1 id="major-features">Major Features</h1>

<h2 id="architecture--platform">Architecture / Platform</h2>

<h3 id="new-architecture-apis">New Architecture APIs</h3>

<p>Building on the new <a href="https://binary.ninja/2025/07/24/5.1-helion.html#custom-basic-block-analysis">architecture APIs added in 5.1</a>, we’ve added a new set of APIs to support standalone function-level lifting. Our initial design for Binary Ninja was optimized for multithreaded analysis with as little state as possible so that each basic block could potentially be analyzed in its own thread. However, for plenty of architectures (including a lot of VM-based ones such as Java, Python bytecode, .NET, etc.), there is far too much state or even metadata at the top of each function. The only way to handle such architectures is to enable a single thread to analyze the entire function. While the ABB feature in 5.1 added support for basic block recovery and analysis in a single thread, in 5.3 we now support full function-level lifting.</p>

<p>Internally, we’re using <a href="https://api.binary.ninja/binaryninja.architecture-module.html#binaryninja.architecture.Architecture.get_instruction_text_with_context">these APIs</a> to work on our upcoming TMS320C6x support, but because we use the same APIs available to third parties, this also means other projects like <a href="https://github.com/ivision-research/banjo">banjo</a> or some of the WASM plugins we’ve heard about could be updated for much better decompilation results using these new APIs.</p>

<p>Keep an eye out for an upcoming blog post explaining more about how you can leverage these APIs yourself!</p>

<h3 id="nds32">NDS32</h3>

<p>Ultimate customers will appreciate the brand new NDS32 support. We now have 18 officially supported architectures including full decompilation in our Ultimate/Enterprise edition!</p>

<p><a href="/blog/images/5.3-release/nds32-decompilation.png"><img src="/blog/images/5.3-release/nds32-decompilation.png" alt="nds32-libstdc++.so decompilation" class="image max-height-500" /></a></p>

<h3 id="aarch64-ilp32-abi">AArch64 ILP32 ABI</h3>

<p>It’s not enough to just have support for the instructions in a CPU architecture since there are lots of platforms or variants that need to be supported. For example, ILP32 adds a mode for AArch64 that has 32-bit pointers despite still using 64-bit mode. In 5.3, we’ve not only <a href="https://github.com/Vector35/binaryninja-api/commit/d634a5d6527f7ec203907f17cde8d0d807028fe3">added the platform</a>, but also <a href="https://github.com/Vector35/binaryninja-api/commit/6be9a1fce3d750613d2605c57f0c911d5dc569d0">updated our function recognizer</a> for ILP32 PLT entries and <a href="https://github.com/Vector35/binaryninja-api/commit/c762640d97a6302e9e2a8a5afcc62a6b1a100e7b">fixed a bug</a> related to the address size calculation.</p>

<div class="juxtapose max-height-600" style="margin-bottom: 1rem;">
  <img data-label="ILP32 5.3 (New)" src="/blog/images/5.3-release/ilp32-new.png" />
  <img data-label="ILP32 5.2 (Old)" src="/blog/images/5.3-release/ilp32-old.png" />
</div>

<h2 id="ui">UI</h2>

<p><a href="/blog/images/5.3-release/macho-picker.png"><img src="/blog/images/5.3-release/macho-picker.png" alt="Mach-O Picker &gt;" class="image max-height-300" /></a></p>

<h3 id="mach-o-architecture-picker">Mach-O Architecture Picker</h3>

<p>While it’s long been possible to open a specific slice in a fat Mach-O or even adjust your settings to default to a particular slice, the UI around it was fairly painful, reusing our “Open With Options” dialog in a way that led to a lot of confusion.</p>

<p>In 5.3, you now get a much more streamlined dialog that lets you pick the architecture and, more importantly, makes it easy to set the default for future opens without having to dig through the <a href="https://docs.binary.ninja/guide/settings.html">settings</a>! The dialog also shows the size of each slice, so you can quickly identify the one you need.</p>

<h3 id="container-browser-improvements">Container Browser Improvements</h3>

<p>We first introduced the <a href="https://binary.ninja/2025/11/13/binary-ninja-5.2-io.html#container-support">Container Browser in 5.2</a>; however, we’ve made a number of improvements to both the container system and to the formats it supports!</p>

<p><strong>Already Supported Formats:</strong> CaRT, Gzip, IntelHex, LZFSE, SRec, TiTxt, Zip, Zlib</p>

<p><strong>New In 5.3:</strong> AR, Bzip2, CPIO, DMG (compression only), FIT, IMG4/KernelCache, LZ4Frame, LZMA, Tar, TRX, UImage, Universal Mach-O, XZ, Zstd</p>

<p>The Container Browser UI itself has also had a number of improvements, as well. It now remembers your most recent selection, can be triggered for files explicitly from the file menu (or by holding Ctrl+Alt and dragging/dropping), and the UI has been refreshed.</p>

<p>We’ve also added better documentation about the <a href="https://docs.binary.ninja/dev/containertransforms.html">transform system</a> and <a href="https://docs.binary.ninja/guide/index.html#working-with-containers">UI</a>.</p>

<p><a href="/blog/images/5.3-release/container-browser.png"><img src="/blog/images/5.3-release/container-browser.png" alt="Updated Container Browser UI" class="image max-height-500" /></a></p>

<h3 id="command-palette-refresh">Command Palette Refresh</h3>

<p><a href="/blog/images/5.3-release/command-palette.png"><img src="/blog/images/5.3-release/command-palette.png" alt="New features in the command palette &gt;" class="image max-height-300" /></a></p>

<p>While we’ve had our <a href="https://docs.binary.ninja/guide/index.html#command-palette">command-palette</a> for some time, in 5.3 we’ve turbocharged it with a ton of new features. You can prefix your search with various characters to get different behaviors. Note that the default CTRL/CMD-P hotkey defaults to “action search” (the previous behavior) but can be rebound to use any of the new behaviors.</p>

<ul>
  <li><code class="language-plaintext highlighter-rouge">=</code> Use the expression parser to calculate an address and navigate there (including a preview)</li>
  <li><code class="language-plaintext highlighter-rouge">&gt;</code> Action search, the previous default</li>
  <li><code class="language-plaintext highlighter-rouge">/</code> Search recent files and projects, as well as open tabs</li>
  <li><code class="language-plaintext highlighter-rouge">@</code> Search function symbols (similar to searching in the symbol sidebar)</li>
  <li><code class="language-plaintext highlighter-rouge">?</code> Display available search prefixes</li>
  <li><code class="language-plaintext highlighter-rouge">t:</code> Just search open tabs (useful as a bindable hotkey)</li>
  <li><code class="language-plaintext highlighter-rouge">"</code> Search strings</li>
</ul>

<p>For more details, check out our <a href="https://binary.ninja/2026/02/05/command-palette-updates.html">recent blog post about it</a>.</p>

<h2 id="types--signatures">Types &amp; Signatures</h2>

<h3 id="type-library-utilities">Type Library Utilities</h3>

<p>One of our major focus areas currently is our type system and how we collect, manage, and apply types. To that end, this release includes a new set of utilities to handle type libraries. This can be used to automatically create usable type libraries from a binary view or from files in a directory. For users with project support (currently commercial and above), type libraries can also be generated from files in a project.</p>

<p>See the <code class="language-plaintext highlighter-rouge">BNTL</code> plugin menu for the available commands:</p>

<p><a href="/blog/images/5.3-release/bntl-menu.png"><img src="/blog/images/5.3-release/bntl-menu.png" alt="BNTL plugin menu options" class="image max-height-400" /></a></p>

<p><a href="/blog/images/5.3-release/bntl-creation.png"><img src="/blog/images/5.3-release/bntl-creation.png" alt="UI Showing BNTL creation from a directory of headers" class="image max-height-300" /></a></p>

<p>There’s also a <a href="https://github.com/Vector35/binaryninja-api/blob/dev/plugins/bntl_utils/cli/README.md">command-line version</a> for headless automation for customers with headless support:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>/t/bntl_utils_cli &gt; ./bntl_cli --help
Generate, inspect, and validate Binary Ninja type libraries (BNTL)

Usage: bntl_cli &lt;COMMAND&gt;

Commands:
  create    Create a new type library from a set of files
  dump      Dump the type library to a C header file
  diff      Generate a diff between two type libraries
  validate  Validate the type libraries for common errors
  help      Print this message or the help of the given subcommand(s)

Options:
  -h, --help     Print help
  -V, --version  Print version
/t/bntl_utils_cli &gt; ls -l
total 13728
-rwxr-xr-x  1 jwiens  wheel  5498296 Apr  9 11:23 bntl_cli*
drwxr-xr-x  4 jwiens  wheel      128 Apr  9 11:37 headers/
/t/bntl_utils_cli &gt; ls -l headers/
total 1360
-rw-r--r--@ 1 jwiens  wheel  690055 Apr  9 11:35 sqlite3.h
-rw-r--r--  1 jwiens  wheel     286 Apr  9 11:37 stdarg.h
/t/bntl_utils_cli &gt; ./bntl_cli create sqlite3.dll "windows-x86_64" ./headers/ ./output |grep -v "Loaded native"
2026-04-09T15:40:37.966972Z  WARN binaryninja: User plugins disabled from command-line override logger=Default
2026-04-09T15:40:39.381327Z  INFO binaryninja: 10021 bundled types for platform windows-x86_64 loaded logger=Platform
2026-04-09T15:40:39.381337Z  INFO binaryninja: 0 bundled variables for platform windows-x86_64 loaded logger=Platform
2026-04-09T15:40:39.381339Z  INFO binaryninja: 77 bundled functions for platform windows-x86_64 loaded logger=Platform
2026-04-09T15:40:39.384452Z  INFO binaryninja: 1 types for platform windows-x86_64 loaded logger=Platform
2026-04-09T15:40:39.384459Z  INFO binaryninja: 0 variables for platform windows-x86_64 loaded logger=Platform
2026-04-09T15:40:39.384461Z  INFO binaryninja: 0 functions for platform windows-x86_64 loaded logger=Platform
2026-04-09T15:40:39.677619Z  INFO bntl_cli::create: Created type library 'sqlite3.dll': ./output/x86_64/sqlite3.dll.bntl
</code></pre></div></div>

<p>Keep an eye out for an upcoming blog post that will include more details about how these tools can make your life easier.</p>

<h3 id="warp-improvements">WARP Improvements</h3>

<p>Last release, <a href="https://binary.ninja/2025/11/13/binary-ninja-5.2-io.html#warp-server">we added networked functionality to WARP</a>, our tool for matching previously identified functions. This allowed users to push and pull function information from our server. Additionally, the <a href="https://binary.ninja/2026/01/26/enterprise-2.0.html">v2 enterprise server release</a> included a built-in WARP server for our enterprise customers. For this release we are continuing to improve the UX of interacting with the WARP server.</p>

<p>Pushing signatures is more straightforward with a new UI, and fetching signatures from the server uses less bandwidth by performing server-side matching.</p>

<p><a href="/blog/images/5.3-release/warp-push-dialog.png"><img src="/blog/images/5.3-release/warp-push-dialog.png" alt="New dialog for pushing WARP data to a server" class="image max-height-500" /></a></p>

<p>For this release, we also deprecated SigKit (which can be re-enabled with <code class="language-plaintext highlighter-rouge">analysis.signatureMatcher.autorun</code>), with its removal scheduled for <em>next release</em>. To that end, we bundled signatures for common Linux libraries (<code class="language-plaintext highlighter-rouge">libc6</code>, <code class="language-plaintext highlighter-rouge">libgcc</code>, <code class="language-plaintext highlighter-rouge">libstdc++</code>) to finalize the migration from SigKit to WARP. These signatures are available for <code class="language-plaintext highlighter-rouge">x86</code>, <code class="language-plaintext highlighter-rouge">x86_64</code>, <code class="language-plaintext highlighter-rouge">aarch64</code>, and <code class="language-plaintext highlighter-rouge">armv7</code>.</p>

<h2 id="interoperability">Interoperability</h2>

<h3 id="ghidra-export">Ghidra Export</h3>

<p>We added <a href="https://binary.ninja/2025/11/13/binary-ninja-5.2-io.html#ghidra-import">Ghidra Import in Binary Ninja 5.2</a>, and now we’ve come full circle with <a href="https://docs.binary.ninja/guide/migration/ghidra/ghidraexport.html">Ghidra Export</a> capabilities in 5.3.</p>

<p>First, use the plugin menu to export a <code class="language-plaintext highlighter-rouge">.gzf</code> file:</p>

<p><a href="/blog/images/5.3-release/ghidra-export-menu.png"><img src="/blog/images/5.3-release/ghidra-export-menu.png" alt="&quot;Plugins&quot; / &quot;Ghidra&quot; / &quot;Export View&quot;" class="image max-height-300" /></a></p>

<p>Next, import the file into Ghidra:</p>

<div class="figure-row">
  <figure>
    <a href="/blog/images/5.3-release/ghidra-import-file.png"><img class="image" src="/blog/images/5.3-release/ghidra-import-file.png" alt="Use the File / Import File menu in Ghidra" /></a>
    <figcaption>Import File menu</figcaption>
  </figure>
  <figure>
    <a href="/blog/images/5.3-release/ghidra-loading-gzf.png"><img class="image" src="/blog/images/5.3-release/ghidra-loading-gzf.png" alt="Ghidra loading the GZF" /></a>
    <figcaption>Loading the GZF</figcaption>
  </figure>
</div>

<p>That’s it! Now you’ll have all the types, symbols, bookmarks, comments, function starts, etc. that you had in Binary Ninja in Ghidra:</p>

<div class="figure-row">
  <figure>
    <a href="/blog/images/5.3-release/ghidra-export-comparison-1.png"><img class="image" src="/blog/images/5.3-release/ghidra-export-comparison-1.png" alt="Binary Ninja" /></a>
    <figcaption>Binary Ninja</figcaption>
  </figure>
  <figure>
    <a href="/blog/images/5.3-release/ghidra-export-comparison-2.png"><img class="image" src="/blog/images/5.3-release/ghidra-export-comparison-2.png" alt="Ghidra (after export)" /></a>
    <figcaption>Ghidra (after export)</figcaption>
  </figure>
</div>

<h3 id="idb-import-improvements">IDB Import Improvements</h3>

<p>With this release, we overhauled our IDB (and TIL) <a href="https://docs.binary.ninja/guide/migration/migrationguideida.html#importing-data">import functionality</a>. This new version processes more information and will work with many more IDA databases.</p>

<div class="notification is-info is-light" role="status">
<b>Note:</b> Instead of just applying an IDB after loading a binary, you can now set <code>analysis.idb.autoLoadFile</code> to the desired IDB path using the "Open with Options" menu. This will improve analysis time by minimizing the need for linear sweep function discovery. You can also use the "Load IDB" action after a file has been loaded. This replaces the previous behavior of using "Import Debug Info From External File...," which was far less discoverable.
</div>

<div class="juxtapose max-height-600" style="margin-bottom: 1rem;">
  <img data-label="New IDB Import" src="/blog/images/5.3-release/idb-import-new.png" />
  <img data-label="Previous IDB Import" src="/blog/images/5.3-release/idb-import-old.png" />
</div>

<h2 id="enterprise">Enterprise</h2>

<p>The biggest feature for Enterprise in 5.3 is that this is the first stable release since we launched our <a href="https://binary.ninja/2026/01/26/enterprise-2.0.html">v2 Enterprise server</a>. The new server comes with a number of major features:</p>

<ul>
  <li>Bundled <a href="https://binary.ninja/2025/11/13/binary-ninja-5.2-io.html#warp-server">WARP server</a></li>
  <li>Server-wide search APIs</li>
  <li>Official rootless Podman support</li>
  <li>New deployment options</li>
</ul>

<p>Check out the <a href="https://binary.ninja/2026/01/26/enterprise-2.0.html">release blog post</a> for more details. We encourage all Enterprise customers to migrate to v2, but we do plan to maintain the v1 server for some additional time to ease the transition.</p>

<h2 id="debugger">Debugger</h2>

<h3 id="hardware-and-conditional-breakpoints">Hardware and Conditional Breakpoints</h3>

<p>Two of our most requested debugger features are finally here: <a href="https://docs.binary.ninja/guide/debugger/index.html#addremove-hardware-breakpoints">hardware breakpoints</a> and <a href="https://docs.binary.ninja/guide/debugger/index.html#set-conditional-breakpoints">conditional breakpoints</a>, making your debugging workflow much more flexible.</p>

<p>To add a hardware breakpoint, press <code class="language-plaintext highlighter-rouge">F3</code> or use <code class="language-plaintext highlighter-rouge">Debugger</code> / <code class="language-plaintext highlighter-rouge">Add Hardware Breakpoint...</code> (also available by right-clicking in the <a href="https://docs.binary.ninja/guide/debugger/index.html#breakpoint-widget">Breakpoint Widget</a>). The dialog lets you pick the address, type (<code class="language-plaintext highlighter-rouge">Hardware Execute</code>, <code class="language-plaintext highlighter-rouge">Read</code>, <code class="language-plaintext highlighter-rouge">Write</code>, or <code class="language-plaintext highlighter-rouge">Access</code>), watchpoint size (1, 2, 4, or 8 bytes), and the entries show up in the Breakpoint Widget tagged <code class="language-plaintext highlighter-rouge">HE</code>/<code class="language-plaintext highlighter-rouge">HR</code>/<code class="language-plaintext highlighter-rouge">HW</code>/<code class="language-plaintext highlighter-rouge">HA</code>.</p>

<p>Conditional breakpoints attach to any existing breakpoint: right-click on a breakpoint (in either the <a href="https://docs.binary.ninja/guide/debugger/index.html#breakpoint-widget">Breakpoint Widget</a> or the disassembly view) and choose <code class="language-plaintext highlighter-rouge">Edit Condition...</code>. Conditions support register names, arithmetic, comparisons, and memory dereferences (e.g., <code class="language-plaintext highlighter-rouge">rax == 0x1234</code>, <code class="language-plaintext highlighter-rouge">[rsp + 0x20] != 0</code>), and execution only pauses when the expression evaluates to non-zero.</p>

<div class="figure-row figure-row-compact">
  <figure>
    <a href="/blog/images/5.3-release/hardware-breakpoint.png"><img class="image" src="/blog/images/5.3-release/hardware-breakpoint.png" alt="Add Hardware Breakpoint dialog" /></a>
    <figcaption>Hardware breakpoint</figcaption>
  </figure>
  <figure>
    <a href="/blog/images/5.3-release/conditional-breakpoint.png"><img class="image" src="/blog/images/5.3-release/conditional-breakpoint.png" alt="Edit Condition dialog" /></a>
    <figcaption>Conditional breakpoint</figcaption>
  </figure>
</div>

<h3 id="new-debug-adapters">New Debug Adapters</h3>

<p>Two new debug adapters ship with 5.3:</p>

<p>The <strong>Windows Native Debug Adapter</strong> is a brand-new adapter built on top of the Windows debugging APIs and is now the default debugger on Windows. It comes with major performance improvements over the previous DbgEng-based adapter.</p>

<p>The <strong>GDB MI Adapter</strong> provides a new way to connect to GDB-compatible targets using the GDB Machine Interface protocol, fixing many corner cases in the previous GDB RSP adapter. It works seamlessly with gdbserver or GDB stubs such as those from QEMU, and includes support for TTD (Time Travel Debugging) via Mozilla’s <a href="https://rr-project.org/">rr</a>. Currently Linux-only, with Windows and macOS support planned.</p>

<h2 id="crash-reporting">Crash Reporting</h2>

<p><a href="/blog/images/5.3-release/crash-reporting.png"><img src="/blog/images/5.3-release/crash-reporting.png" alt="Crash reporting opt-in prompt &gt;" class="image max-height-300" /></a></p>

<p>To ensure we can fix issues faster, in 5.3 we’ve added opt-in <a href="https://docs.binary.ninja/about/privacy.html#crash-reporting">automatic crash reporting</a>. The first time you launch 5.3 (unless you’ve already seen it on dev) you’ll see a prompt asking whether you’d like to share crash reports with us. In paid versions, it’s disabled by default. In the Free version, it’s enabled by default but you can still opt-out and you can change your mind at any time by changing the appropriate <a href="https://docs.binary.ninja/guide/settings.html#crashReporting.enabled">setting</a>.</p>

<p>When enabled, a crash report contains:</p>
<ul>
  <li>the OS version</li>
  <li>Binary Ninja version</li>
  <li>CPU architecture</li>
  <li>call stack at the time of the crash</li>
  <li>a list of loaded native libraries</li>
</ul>

<p>No binary content or identifying information is intentionally included, though application and plug-in paths may contain your system username. Full details are in our <a href="https://docs.binary.ninja/about/privacy.html#crash-reporting">privacy policy</a>.</p>

<p>If you want to help us fix bugs faster, we’d appreciate enabling crash reporting but absolutely understand for many this is not desired which is why we default to NOT sending this information.</p>

<h1 id="open-source-contributions">Open-Source Contributions</h1>

<p>Special thanks to the following open source contributors whose PRs were merged into this release:</p>

<ul>
  <li><a href="https://github.com/3rdit">3rdit</a> [<a href="https://github.com/Vector35/debugger/pull/941">#941</a>, <a href="https://github.com/Vector35/debugger/pull/943">#943</a>, <a href="https://github.com/Vector35/debugger/pull/944">#944</a>, <a href="https://github.com/Vector35/debugger/pull/946">#946</a>, <a href="https://github.com/Vector35/debugger/pull/947">#947</a>, <a href="https://github.com/Vector35/debugger/pull/969">#969</a>, <a href="https://github.com/Vector35/debugger/pull/1026">#1026</a>]</li>
  <li><a href="https://github.com/chedahub">chedahub</a> [<a href="https://github.com/Vector35/binaryninja-api/pull/7552">#7552</a>]</li>
  <li><a href="https://github.com/ekilmer">ekilmer</a> [<a href="https://github.com/Vector35/binaryninja-api/pull/7547">#7547</a>]</li>
  <li><a href="https://github.com/jonpalmisc">jonpalmisc</a> [<a href="https://github.com/Vector35/binaryninja-api/pull/7933">#7933</a>]</li>
  <li><a href="https://github.com/mostobriv">mostobriv</a> [<a href="https://github.com/Vector35/binaryninja-api/pull/7751">#7751</a>]</li>
  <li><a href="https://github.com/NicoleFaye">NicoleFaye</a> [<a href="https://github.com/Vector35/debugger/pull/962">#962</a>, <a href="https://github.com/Vector35/debugger/pull/983">#983</a>, <a href="https://github.com/Vector35/debugger/pull/991">#991</a>]</li>
  <li><a href="https://github.com/nullableVoidPtr">nullableVoidPtr</a> [<a href="https://github.com/Vector35/binaryninja-api/pull/6423">#6423</a>, <a href="https://github.com/Vector35/binaryninja-api/pull/7965">#7965</a>]</li>
  <li><a href="https://github.com/razaina">razaina</a> [<a href="https://github.com/Vector35/debugger/pull/1004">#1004</a>, <a href="https://github.com/Vector35/debugger/pull/1005">#1005</a>, <a href="https://github.com/Vector35/debugger/pull/1006">#1006</a>]</li>
  <li><a href="https://github.com/SmoothHacker">SmoothHacker</a> [<a href="https://github.com/Vector35/binaryninja-api/pull/7780">#7780</a>, <a href="https://github.com/Vector35/binaryninja-api/pull/7788">#7788</a>]</li>
  <li><a href="https://github.com/trumank">trumank</a> [<a href="https://github.com/Vector35/binaryninja-api/pull/7797">#7797</a>, <a href="https://github.com/Vector35/binaryninja-api/pull/7825">#7825</a>]</li>
  <li><a href="https://github.com/utkonos">utkonos</a> [<a href="https://github.com/Vector35/binaryninja-api/pull/7748">#7748</a>, <a href="https://github.com/Vector35/binaryninja-api/pull/7773">#7773</a>, <a href="https://github.com/Vector35/binaryninja-api/pull/7776">#7776</a>, <a href="https://github.com/Vector35/binaryninja-api/pull/7839">#7839</a>, <a href="https://github.com/Vector35/binaryninja-api/pull/7855">#7855</a>]</li>
  <li><a href="https://github.com/WHW0x455">WHW0x455</a> [<a href="https://github.com/Vector35/binaryninja-api/pull/7842">#7842</a>]</li>
</ul>

<p>We appreciate your contributions!</p>

<h1 id="everything-else">Everything Else</h1>

<h2 id="analysis--core">Analysis / Core</h2>

<ul>
  <li><strong>Feature</strong>: Added <code class="language-plaintext highlighter-rouge">ZxTransform</code> to the transform system</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/ccc1fb197dd97e000427dadb40f167ccd7b1c2f9">work provider signals for activity eligibility</a> in workflows</li>
  <li><strong>Feature</strong>: Added backward constraint propagation support to the Value Set Analysis (VSA) system</li>
  <li><strong>Feature</strong>: Added <code class="language-plaintext highlighter-rouge">PossibleValueSet::Compare</code> to resolve set and range comparisons to constants</li>
  <li><strong>Improvement</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/9bb8792f6be698ed9f2bd6e1dc555bfd91709044"><code class="language-plaintext highlighter-rouge">PossibleValueSet</code></a> operation APIs and fixed Python <code class="language-plaintext highlighter-rouge">PossibleValueSet</code> bindings</li>
  <li><strong>Improvement</strong>: Extracted thunk analysis into a standalone pass, decoupling it from the sigkit plugin to prepare for sigkit deprecation</li>
  <li><strong>Improvement</strong>: Improved <a href="https://github.com/Vector35/binaryninja-api/commit/0facabad207dba55ff77f8af6de9e82a95f62080">entry point detection</a> to differentiate between a <code class="language-plaintext highlighter-rouge">0x0</code> entry address and no entry at all</li>
  <li><strong>Improvement</strong>: Improved <a href="https://github.com/Vector35/binaryninja-api/commit/9d6b64e8697ec85e8111b3d847b3e6d5853cf599">GNU3 demangler</a> with support for new special-name and type constructs</li>
  <li><strong>Improvement</strong>: Improved <a href="https://github.com/Vector35/binaryninja-api/commit/e299a6c1bf74f0ca6d2c3d79135e8c23e6b9fbba">RTTI virtual function discovery</a> to allow extern functions in MSVC vtables</li>
  <li><strong>Improvement</strong>: Improved auto-naming of variables using parameter names from tail call targets</li>
  <li><strong>Improvement</strong>: Improved memory efficiency of <a href="https://github.com/Vector35/binaryninja-api/commit/25213a836b1423cbc1aeef1f23aebc2167154e56">operand lists and label maps</a> within IL instructions by replacing <code class="language-plaintext highlighter-rouge">UNDEF</code> instruction chains with a more compact representation</li>
  <li><strong>Improvement</strong>: Improved performance by generating structure padding lazily</li>
  <li><strong>Improvement</strong>: Improved performance of <code class="language-plaintext highlighter-rouge">canMakeString</code> by avoiding large scans for null terminators in UTF-16 and UTF-32 strings</li>
  <li><strong>Improvement</strong>: Improved performance of non-namespaced type lookup in large BNDBs</li>
  <li><strong>Improvement</strong>: Improved type propagation around offset pointers for better type inference</li>
  <li><strong>Improvement</strong>: Moved zero-length section filtering from <code class="language-plaintext highlighter-rouge">SectionMap</code> to section creation APIs for more consistent behavior</li>
  <li><strong>Improvement</strong>: Reduced map lookups during MLIL SSA translation for a 2-5% improvement in total analysis time</li>
  <li><strong>Improvement</strong>: Reduced memory usage of function objects by 70% and their analysis data by 40% by restructuring storage of infrequently set fields</li>
  <li><strong>Improvement</strong>: Represent operand lists and label maps more efficiently within IL instructions, replacing chains of <code class="language-plaintext highlighter-rouge">UNDEF</code> instructions</li>
  <li><strong>Improvement</strong>: Rewrote <a href="https://github.com/Vector35/binaryninja-api/commit/260ca61d94134b6743807e29f64b5ce4f6918d73">GNU3 demangler</a> for improved performance using <code class="language-plaintext highlighter-rouge">DemangledTypeNode</code></li>
  <li><strong>Improvement</strong>: Scoped <a href="https://github.com/Vector35/binaryninja-api/commit/b079771e37b1f8277a815ee089e012f9130be2a4">RTTI loggers</a> to their associated view for cleaner log output</li>
  <li><strong>Improvement</strong>: Simplified HLIL expressions <code class="language-plaintext highlighter-rouge">(X &lt;&lt; Y) u&gt;&gt; Y</code> and <code class="language-plaintext highlighter-rouge">(X u&gt;&gt; Y) &lt;&lt; Y</code></li>
  <li><strong>Fix</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/bcc40473b3660005e83f51150bdc17ae177768dc">validation for zero-sized symbol or string tables</a> to prevent potential issues during analysis</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/213b1487db828d26aa2f60d9fb2d7f990d9fd43b">crash when <code class="language-plaintext highlighter-rouge">readLEB128</code> is passed a null pointer</a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/1c0569fbe6e9f9f390d22062425fbf95f5c56576">crash when displaying a variable with null type</a> in Pseudo-C and Pseudo-Rust</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/e4dc9f370f948bf8071e38667fc9606f13ea0f70">DWARF import incorrectly linking functions without addresses to externs</a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/9b7604d13e8bd98c6998facb9326926ed96281b5">DWARF import incorrectly wrapping pointer types in named type references</a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/30cb29617d0db9f5953c7468f208e33920a2239d">DWARF import wrapping function parameter types</a> in unnecessary named type references</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/1743bbaa43911306229a8ecf0c0184f8eb79f435">GNU3 demangler float literal decoding</a> to be platform-independent by using big-endian hex via union type-punning</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/e5c73ffdf3d1914596f0ffd1c989330657934627">headless mode being prompted with an interaction for mismatched PDB</a> during PDB import</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/a83f2082799695b85b732987adb21112d042b152">PDB bitfield members importing with wrong offset</a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/9dbc09db3ad16db41cddcd98258c00c829924270">PDB parsing issue</a> by removing stale <code class="language-plaintext highlighter-rouge">QualifiedName</code> state</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/ca91bc1933976c62d24248f0f7c35af38451ff11">potential hang in DWARF import</a> when encountering unhandled <code class="language-plaintext highlighter-rouge">DW_AT_location</code> variants for <code class="language-plaintext highlighter-rouge">DW_TAG_variable</code></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/339ce9d5b3a1b6e116c7cd43349a3d935959ee35">undefined evaluation order in GNU3 demangler expression builders</a> by sequencing reader-advancing calls into named locals</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/99194f432a4dad6938497e7d54ccb0d812dfacac">use of uninitialized stack data in ABB</a></li>
  <li><strong>Fix</strong>: Fixed PDB <a href="https://github.com/Vector35/binaryninja-api/commit/f80ecd096f75eb3f412e36219c5e83dc94dd4896">vtable type name parsing</a></li>
  <li><strong>Fix</strong>: Fixed <code class="language-plaintext highlighter-rouge">Analysis::DeleteUnusedAutoFunctions</code> hanging for many minutes on large binaries with over 1 million functions</li>
  <li><strong>Fix</strong>: Fixed <code class="language-plaintext highlighter-rouge">FloatType</code> alternate name not rendering in tokens when set</li>
  <li><strong>Fix</strong>: Fixed <code class="language-plaintext highlighter-rouge">LowLevelILFunction::GetInstructionsAt</code> not working on SSA form</li>
  <li><strong>Fix</strong>: Fixed <code class="language-plaintext highlighter-rouge">MLILSSATranslator</code> not consulting the Platform for global register information</li>
  <li><strong>Fix</strong>: Fixed <code class="language-plaintext highlighter-rouge">WorkflowMachine</code> task name when resuming from an inactive state</li>
  <li><strong>Fix</strong>: Fixed additional invalid ELF parsing issues</li>
  <li><strong>Fix</strong>: Fixed anonymous type names conflicting with existing anonymous types</li>
  <li><strong>Fix</strong>: Fixed crash in <code class="language-plaintext highlighter-rouge">OutlineResolver</code> caused by cycles involving named type references</li>
  <li><strong>Fix</strong>: Fixed crash in <code class="language-plaintext highlighter-rouge">WorkflowMachine</code> when a workflow activity threw an exception</li>
  <li><strong>Fix</strong>: Fixed crash when mapping to HLIL with a <code class="language-plaintext highlighter-rouge">void</code> variable type and an MLIL pointer expression type</li>
  <li><strong>Fix</strong>: Fixed crash when opening a BNDB that references a non-existent named workflow</li>
  <li><strong>Fix</strong>: Fixed data races in <code class="language-plaintext highlighter-rouge">Function</code> that could cause crashes during analysis</li>
  <li><strong>Fix</strong>: Fixed FlexHex high nibble wildcard matching false positives on <code class="language-plaintext highlighter-rouge">0x7c</code></li>
  <li><strong>Fix</strong>: Fixed forward type propagation to preserve <code class="language-plaintext highlighter-rouge">NamedTypeReference</code>s instead of resolving them to raw structs</li>
  <li><strong>Fix</strong>: Fixed hang on close during pointer sweep analysis</li>
  <li><strong>Fix</strong>: Fixed HLIL call rendering to correctly consider call type adjustments when displaying calls and parameter strings</li>
  <li><strong>Fix</strong>: Fixed incorrect file backing when a memory region starts past the segment data length</li>
  <li><strong>Fix</strong>: Fixed infinite loop/crash when adding a zero-length section</li>
  <li><strong>Fix</strong>: Fixed lookup of basic block labels for higher-level ILs when the IL block start differs from the native block start</li>
  <li><strong>Fix</strong>: Fixed miscellaneous issues with vtable type information in PDB processing</li>
  <li><strong>Fix</strong>: Fixed non-deterministic tail call detection caused by stale basic blocks</li>
  <li><strong>Fix</strong>: Fixed offset pointers imported with <code class="language-plaintext highlighter-rouge">__offset</code> attribute losing their offset due to struct member relationship not being preserved</li>
  <li><strong>Fix</strong>: Fixed outliner incorrectly outlining scalar struct member writes</li>
  <li><strong>Fix</strong>: Fixed outliner incorrectly outlining scalar struct member writes in arrays-of-structs</li>
  <li><strong>Fix</strong>: Fixed PDB bitfield members importing with incorrect offset when the bitfield is placed at a storage offset greater than zero</li>
  <li><strong>Fix</strong>: Fixed preservation of global pointer register value across call-site stack invalidations</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/c56a37539cbafd3c2a8745138009265a211413b3">Python <code class="language-plaintext highlighter-rouge">ABB</code> incorrectly triggering guided analysis</a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/a10b2f085b75e8681c6534c87a4c5b2ff4efe980">Python exception in <code class="language-plaintext highlighter-rouge">FunctionLifterContext</code></a></li>
  <li><strong>Fix</strong>: Fixed resolution of named type references for child types in <code class="language-plaintext highlighter-rouge">OutlineResolver</code></li>
  <li><strong>Fix</strong>: Fixed template simplifier to correctly account for <code class="language-plaintext highlighter-rouge">[api:...]</code> annotations</li>
  <li><strong>Fix</strong>: Fixed type filtering to correctly respect underscores in type names</li>
  <li><strong>Fix</strong>: Fixed unintentional fallthrough in HLIL simplification that caused exceptions</li>
  <li><strong>Fix</strong>: Improved <code class="language-plaintext highlighter-rouge">OutlineResolver</code> handling when merging different stream types while writing to fully-typed byte arrays</li>
</ul>

<h2 id="ui-1">UI</h2>

<ul>
  <li><strong>Feature</strong>: Added “Copy as Rust Array” to the right-click context menu</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/9f9cf3a2cfb45d2e2f3b3dad704c326114df38eb">go-to address support</a> in the native triage view</li>
  <li><strong>Feature</strong>: Added structure data variables as objects in linear view</li>
  <li><strong>Improvement</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/70bbb18a9444824a8ec2b9a7ff57fc848e017b6e">regex and case sensitivity options to <code class="language-plaintext highlighter-rouge">FilterEdit</code></a> widget</li>
  <li><strong>Improvement</strong>: Added regex toggle to the component tree <code class="language-plaintext highlighter-rouge">FilterEdit</code> widget</li>
  <li><strong>Improvement</strong>: Excluded <code class="language-plaintext highlighter-rouge">.bndb</code> files from the <a href="https://github.com/Vector35/binaryninja-api/commit/c09bba838812f061372349c08984fa7a9355503b">triage file picker</a> to avoid opening database files in triage mode</li>
  <li><strong>Improvement</strong>: Improved <a href="https://github.com/Vector35/binaryninja-api/commit/4023131568543815232094368747147422801198">performance of the types view</a></li>
  <li><strong>Improvement</strong>: Improved <a href="https://github.com/Vector35/binaryninja-api/commit/dbdf3381e2dd32527cffaca6081fc5a9913f1cc7">triage view responsive layout</a> to adapt better to different window sizes</li>
  <li><strong>Improvement</strong>: Improved outliner to recursively resolve nested struct types</li>
  <li><strong>Improvement</strong>: Improved performance of Bookmarks actions by avoiding full function iteration to check validity</li>
  <li><strong>Improvement</strong>: Improved performance of the types view by removing recursive expansion, switching to <code class="language-plaintext highlighter-rouge">unordered_map</code>, and using uniform row heights</li>
  <li><strong>Improvement</strong>: Made analysis conflict dialog labels selectable for easier copying</li>
  <li><strong>Improvement</strong>: Made the cross-reference view non-modal when opened in dialog mode</li>
  <li><strong>Improvement</strong>: Shows function tags in the linear view sticky header</li>
  <li><strong>Improvement</strong>: Sorts menu actions case-insensitively for consistent ordering</li>
  <li><strong>Improvement</strong>: Updated <a href="https://github.com/Vector35/binaryninja-api/commit/f96697f42d7535d8a7ad9d66f965d295b2c2eaf0">entropy tooltip</a> to display file offset and fixed Python version compatibility</li>
  <li><strong>Improvement</strong>: Updated <a href="https://github.com/Vector35/binaryninja-api/commit/26e768701acd4e48d2810c639754b673b99273f0">triage view</a> to only show libraries when appropriate</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/47c90e940e7c3eb61c5a5a3a9702ebe7cd0ea27c"><code class="language-plaintext highlighter-rouge">MemoryRegionDialog</code></a> incorrectly prepopulating length for file-backed regions</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/2a97a8e0cce77c07df207248ca1ad3055e6733c6">crash in <code class="language-plaintext highlighter-rouge">TypeDialog</code></a> when parser results arrived at the wrong time</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/fd8eeb4cc6a4ba19631ef787b3fc505ae2b1eef8">Enter key in the base field of the Create Structure dialog</a> to add the structure instead of dismissing the dialog</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/39da63b33c14cfa3f640a761fad1e27b79f9c91f">long path truncation in triage view</a> and prevented UI from shifting when starting BASE</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/f42a196a21006602b2cc4b1647c2b8189b50b84e">regression preventing navigation back from triage view</a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/0282141c9b70ca8288a9e434e3b78fcfe2d6343b">section list in triage view</a> not updating when sections change</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/b7153854054958c8f362144b59ef05d176c2bb54">settings view layout and resize performance</a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/5b804c2c7bae72ccbc2865002d427b52ac4c0b0f">triage entropy graph navigation</a> for mapped files</li>
  <li><strong>Fix</strong>: Fixed bad indentation for single-line function header comments in Linear View</li>
  <li><strong>Fix</strong>: Fixed bug preventing editing of data comments created at addresses</li>
  <li><strong>Fix</strong>: Fixed crash in Linear View when attempting to define an array</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/a8136a2e13c283171ae5ccca7ce8b02a83e6cdb1">crash in settings view</a></li>
  <li><strong>Fix</strong>: Fixed crash when <code class="language-plaintext highlighter-rouge">get_choice_input</code> is called without an active window</li>
  <li><strong>Fix</strong>: Fixed crash when viewing MLIL debug report caused by basic block annotations using committed IL functions instead of active ones</li>
  <li><strong>Fix</strong>: Fixed duplicated comments in Linear View for objects sharing the same address</li>
  <li><strong>Fix</strong>: Fixed hang when rendering self-referential <code class="language-plaintext highlighter-rouge">typedef</code></li>
  <li><strong>Fix</strong>: Fixed linear view not refreshing when resized vertically</li>
  <li><strong>Fix</strong>: Fixed linear view refresh behavior when resized vertically</li>
  <li><strong>Fix</strong>: Fixed linear view to subscribe to section updates so it reflects changes correctly</li>
  <li><strong>Fix</strong>: Fixed multiple bugs in triage view</li>
  <li><strong>Fix</strong>: Fixed multiple issues in the triage view</li>
  <li><strong>Fix</strong>: Fixed null pointer crashes in the Chat sidebar</li>
  <li><strong>Fix</strong>: Fixed off-by-one error in the array <code class="language-plaintext highlighter-rouge">Copy As</code> action</li>
  <li><strong>Fix</strong>: Fixed parsing of extraneous bytes in search result previews</li>
  <li><strong>Fix</strong>: Fixed potential null pointer crashes in the User Positions sidebar</li>
  <li><strong>Fix</strong>: Fixed single function linear view when the viewed function becomes undefined</li>
  <li><strong>Fix</strong>: Fixed sort order in settings view for settings without a subgroup</li>
  <li><strong>Fix</strong>: Fixed spin boxes consuming scroll events in the settings view</li>
  <li><strong>Fix</strong>: Fixed stack view and variable list sidebars not broadcasting cross-reference selections</li>
  <li><strong>Fix</strong>: Fixed text diffs not respecting UTF-16 encoding of <code class="language-plaintext highlighter-rouge">QString</code>s</li>
  <li><strong>Fix</strong>: Fixed tooltip struct offset resolution to use <code class="language-plaintext highlighter-rouge">ResolveMemberOrBaseMember</code> for improved accuracy</li>
  <li><strong>Fix</strong>: Fixed view state restoration being incorrectly applied when opening files via triage</li>
</ul>

<h2 id="architectures-and-platforms">Architectures and Platforms</h2>

<ul>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/2a4c7d5d89907497e029337bbaf6f7e467bcde98"><code class="language-plaintext highlighter-rouge">GetInstructionTextWithContext</code></a> callback to the architecture class to share context between basic block recovery, lifting, and disassembly</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/3feaf74969b5d855993842e204cab04fb9725165">arm64 calling conventions for the Swift ABI</a>, including repurposed callee-saved registers</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/908a18947d34b06da936a464a69f71e9e0a4eec3">automatic and manual endianness override support</a> for x86 ELF files</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/3eda43f185a0411538745a99e251122e6a9192e0">Intel APX support</a> for x86</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/15e3a9fe618df912948b08c56b10dab035aa8f01">R_386_IRELATIVE relocation handling</a> for x86 ELF binaries</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/7aa5bd46fc2343458dff6a24ec2c67169fcac34c">Swift initial demangling support</a> for Swift symbols</li>
  <li><strong>Feature</strong>: Added <code class="language-plaintext highlighter-rouge">R_CKCORE_PCREL_JSR_IMM26BY2</code> relocation support for C-SKY architecture</li>
  <li><strong>Feature</strong>: Allows architecture plugins to <a href="https://github.com/Vector35/binaryninja-api/commit/5ccef726c0954116f8f4b5d6347e0acdbb0b6ce3">override function lifting and inlining</a> via <code class="language-plaintext highlighter-rouge">LiftFunction</code></li>
  <li><strong>Feature</strong>: Detect Linux <code class="language-plaintext highlighter-rouge">ro_after_init</code> region and synthesize overlay section for improved kernel analysis</li>
  <li><strong>Feature</strong>: Implemented <a href="https://github.com/Vector35/binaryninja-api/commit/770e9c0c75a943cd4d47ba3cb3be936d09a6c86f"><code class="language-plaintext highlighter-rouge">DTPOFF64</code> and <code class="language-plaintext highlighter-rouge">DTPMOD64</code></a> TLS relocations</li>
  <li><strong>Improvement</strong>: Allow deserializing type libraries without registering them</li>
  <li><strong>Improvement</strong>: Lifted <a href="https://github.com/Vector35/binaryninja-api/commit/c52958ee4e31f8c61737cf7d240b0906bcf70ee0">new PPC instructions and fixed MIPS relocation handling</a></li>
  <li><strong>Improvement</strong>: Updated <a href="https://github.com/Vector35/binaryninja-api/commit/52040a4a15fe84461d1e8c1c592c19be840b48ad">AArch64 system registers</a> based on ARM’s 2025-09 data</li>
  <li><strong>Improvement</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/19ea371012f127727a947e144bb7701ca145c135">missing x86_64 relocations</a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/f83b7bd44c3c82cb71237124705d8687e658da4f">handling of relocations for self-bound data symbols</a> in MachO binaries</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/5d7877b807e45c6b58e6beb73ea11d7fe7f4467f">MIPS <code class="language-plaintext highlighter-rouge">jalr</code> instruction</a> incorrectly receiving a default branch type</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/fb764042bc62f61c25dfdce14ccaf8dcb0437fc3"><code class="language-plaintext highlighter-rouge">si_split16</code></a><a href="https://github.com/Vector35/binaryninja-api/commit/fb764042bc62f61c25dfdce14ccaf8dcb0437fc3"> immediate decoding</a> for PPC VLE I16A-form instructions</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/c62a7862a86c7a05732985a7759b66b0035fb356">calling convention applied to <code class="language-plaintext highlighter-rouge">objc_retain_xN</code> / <code class="language-plaintext highlighter-rouge">objc_release_xN</code></a> in the Objective-C runtime type library</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/4bf13779d75176b6fba0c37fe3b614842bffa193">MachO chained fixup relocations</a> not respecting addends</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/44a4945e5c3532dfaccbad3f23622464f0173691">MIPS <code class="language-plaintext highlighter-rouge">jalr[.hb] $zero, $ra</code></a> to be recognized as a return instruction</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/9b03ef651f59a714b45f072d359edd0905d04925">MIPS64 relocation entry parsing</a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/cab23d939b26e62ba3955b4c10e7d8931432a2c8">operand order for several PPC floating point instructions</a> that were reversed</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/f860e52fe85837ba9e1a9df578b54ab12a983089">rounding flag emission</a> on certain x86 floating point instructions</li>
  <li><strong>Fix</strong>: Fixed <code class="language-plaintext highlighter-rouge">FreeFunctionArchContext</code> error logs on Linux</li>
  <li><strong>Fix</strong>: Fixed <code class="language-plaintext highlighter-rouge">LIST_ENTRY</code> type specializations for AMD64 Windows platform</li>
  <li><strong>Fix</strong>: Fixed C-SKY targets and improved <code class="language-plaintext highlighter-rouge">Cpop</code> instruction output</li>
  <li><strong>Fix</strong>: Fixed crash on Windows when setting thread name with invalid characters</li>
  <li><strong>Fix</strong>: Fixed crash when a platform is not registered in the global platform registry</li>
  <li><strong>Fix</strong>: Fixed duplicate type libraries losing named types and objects</li>
  <li><strong>Fix</strong>: Fixed import address symbol size to use platform address size instead of a hardcoded value (except <code class="language-plaintext highlighter-rouge">linux-x32</code> which retains 8-byte pointers)</li>
  <li><strong>Fix</strong>: Fixed lifting bug in Hexagon predicated jumps with intra-packet <code class="language-plaintext highlighter-rouge">p0</code> dependencies</li>
  <li><strong>Fix</strong>: Fixed logic bug affecting <code class="language-plaintext highlighter-rouge">ldq</code>/<code class="language-plaintext highlighter-rouge">stq</code> instruction handling in M-CORE architecture</li>
  <li><strong>Fix</strong>: Fixed panic in C-SKY lifter when setting IL register</li>
  <li><strong>Fix</strong>: Improved register handling safety in C-SKY and M-CORE lifting</li>
</ul>

<h2 id="core-plugins">Core Plugins</h2>

<ul>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/a49c29b7aea694e41fb92b100325ce34affb413f">initial version of a Swift support plugin</a></li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/432e144beeccf1d9a2d9ed9e7d016384eed0bb32">PE resource information parsing and display</a> in triage view</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/1fb9828d1e12f242fa6a53aa43603ae5e556b69d">support for applying parameter and return types during Swift demangling</a> (disabled by default)</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/37a0604d805991b85a0590279ad993a19ddee7bb">whole-file entropy calculation</a> to the triage view</li>
  <li><strong>Feature</strong>: Added LZMA, LZMA2, LZ4 (Block/Frame), LZF, and ZStandard compression transforms</li>
  <li><strong>Feature</strong>: Added support for loading stored files in AES encrypted zips</li>
  <li><strong>Feature</strong>: Added UImage, FIT, and TRX firmware transforms</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binexport/commit/fb21dddf7abc248781056e2cb93e4b63d57d1ebe">quick export action</a> to BinExport plugin</li>
  <li><strong>Improvement</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/efbde23abcf1f38d98a096044e2256c5619f9004">type propagation from <code class="language-plaintext highlighter-rouge">objc_alloc_init</code> and related functions</a> in the Obj-C plugin</li>
  <li><strong>Improvement</strong>: Added NRF52840 to Firmware Ninja board descriptions</li>
  <li><strong>Improvement</strong>: Added support for loading Ghidra 12.0 databases in the Ghidra importer</li>
  <li><strong>Improvement</strong>: Renamed <a href="https://github.com/Vector35/binaryninja-api/commit/456f3c48002abc0c2265363c50913e96e2f629d6"><code class="language-plaintext highlighter-rouge">corePlugins.ghidraImport</code> to <code class="language-plaintext highlighter-rouge">corePlugins.ghidra</code></a></li>
  <li><strong>Improvement</strong>: Improved <a href="https://github.com/Vector35/binaryninja-api/commit/31c0faa9753601eb7d41965ce5d7f96dcef9b71c">DSC section creation performance</a> by deferring section map rebuilds until all sections are added</li>
  <li><strong>Improvement</strong>: Improved <a href="https://github.com/Vector35/binaryninja-api/commit/e1ad1aa09ce9e7760a68a8dc7c2dfe64c02aa100">KernelCache section creation performance</a> by wrapping bulk section additions in <code class="language-plaintext highlighter-rouge">BeginBulkAddSegments</code>/<code class="language-plaintext highlighter-rouge">EndBulkAddSegments</code> to defer section map rebuilds</li>
  <li><strong>Improvement</strong>: Improved <a href="https://github.com/Vector35/binaryninja-api/commit/14a8c76b46354826d79431168749ed81963db034">Mach-O section type identification</a> by properly masking <code class="language-plaintext highlighter-rouge">flags</code> with <code class="language-plaintext highlighter-rouge">SECTION_TYPE</code></li>
  <li><strong>Improvement</strong>: Improved <a href="https://github.com/Vector35/binaryninja-api/commit/20adc82b8f85a78fe2cd6ddc2b3a8c78558999a5">Obj-C analysis</a> to set return types on <code class="language-plaintext highlighter-rouge">objc_msgSend</code> calls that send an <code class="language-plaintext highlighter-rouge">init</code> message to a known class</li>
  <li><strong>Improvement</strong>: Improved performance of loading many images from the shared cache after introduction of <code class="language-plaintext highlighter-rouge">SectionMap</code></li>
  <li><strong>Improvement</strong>: Improved Zlib transform diagnostics by surfacing inflate errors and warning on likely false positive decompression</li>
  <li><strong>Improvement</strong>: Removed the <code class="language-plaintext highlighter-rouge">add bitfield</code> setting from <a href="https://github.com/Vector35/binaryninja-api/commit/7d672a27f258a9e0057a8aa91938b735276d2897">SVD Import</a> as bitfields are now always included with correct type system representation</li>
  <li><strong>Improvement</strong>: Set <a href="https://github.com/Vector35/binaryninja-api/commit/c5cffef8306d7cec365d8ea75f45cd9f5acf4811">segment flags for MachO kernel images</a> based on how XNU initially maps them</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/4573354f23da495099983dac4b665988cd837ff5">crash when parsing ELF files</a> with empty <code class="language-plaintext highlighter-rouge">.interp</code> or <code class="language-plaintext highlighter-rouge">.dynamic</code> sections</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/c9dbb48365bf1a0c5c06daa2234e21e64d9bc2f7">DSC symbols</a> to correctly reflect local, global, or weak binding</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/d92b3684825220345b902f93b22b160e9401012b">incorrect handling of <code class="language-plaintext highlighter-rouge">BIND_SPECIAL_DYLIB_\*_LOOKUP</code> modes</a> in MachO chained fixups where negative-encoded library values were mishandled</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/a72b98ed5a357bb380d81f07f3f36946aa729bb2">intermittent unrelocated pointers in DSC</a> caused by <code class="language-plaintext highlighter-rouge">FileAccessorCache</code> LRU eviction discarding mapped files</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/e902d25c22f2bf1426d2619933587ace06a38921">Obj-C plugin overriding the <code class="language-plaintext highlighter-rouge">core.function.metaAnalysis</code> workflow description</a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/0a356578e65cf54c5b654b59a509c2ebe29ab54b">Objective-C metadata not being processed</a> when loading a DSC view from a <code class="language-plaintext highlighter-rouge">.bndb</code></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/4e72219707ba28e7ca18816cb74c664006696d99">reading dynamic string tables at large offsets</a> in ELF files</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/318f0bda9695a25320a382aa8c1757804c1ff5e4">SVD import mapper issue</a> where unordered register fields caused spurious <code class="language-plaintext highlighter-rouge">__offset</code> fields to appear in structures</li>
  <li><strong>Fix</strong>: Fixed Ghidra import to use address size from the Ghidra database for default pointer width</li>
  <li><strong>Fix</strong>: Fixed Ghidra importer generating empty function types when function parameters are uncommitted</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/2b1fc96ebb746ee95c12b5a35cd4ffbe9a83d73e">MachO weak bound symbols</a> being incorrectly resolved to their import address</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/81b2d4d06826abc2bbfb658831643c69e453c461">nondeterminism in WARP matching</a> by allowing multi-round matching to resolve function dependencies during parallelized analysis</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/61e4e7e772b9c427bf190f8557afc466d0488848">WARP relocatable region selection</a> to properly fall back to section collection when segment list is used</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/7a4114bae3009c0b52fe2490b08db14463a39a47">WARP server URL sanitization</a> to handle malformed inputs</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/f852785e4ae0eb9bd560566221e9f6d70c895b32">WARP sidebar not showing selected function</a> when opening the sidebar for the first time</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/tree/dev/plugins/warp/examples/headless">warp_headless example</a> not linking <code class="language-plaintext highlighter-rouge">binaryninjacore</code>, which prevented it from loading</li>
</ul>

<h2 id="collaboration--projects">Collaboration / Projects</h2>

<ul>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/e684f8294981aa4287f513dfb9e842177c99d428">table view and miscellaneous fixes and improvements</a> to the Project Browser</li>
  <li><strong>Feature</strong>: Added support for function value stores in collaboration</li>
  <li><strong>Improvement</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/82b1b5cb1d0081044800da11bf31d805b50fd80f"><code class="language-plaintext highlighter-rouge">Open Selected Files with Container Browser...</code></a> option to the project browser context menu</li>
  <li><strong>Improvement</strong>: Improved <a href="https://github.com/Vector35/binaryninja-api/commit/15a836af4ae798a1d030394e872781ca381cf844">container-aware display names</a> in projects</li>
  <li><strong>Improvement</strong>: Improved <code class="language-plaintext highlighter-rouge">Save As</code> behavior when working with project files</li>
  <li><strong>Improvement</strong>: Separated recent file and project states to track them independently</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/22a29f05cf59645a589f63a70269205bb6e9fa83">HTTP requests retrying during shutdown</a> to prevent hangs or errors on exit</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/896f4b96b3f8e6f62e5fdd03803fdfc399db9c5d">improper variable cast in <code class="language-plaintext highlighter-rouge">databasesync.py</code></a></li>
  <li><strong>Fix</strong>: Fixed crash when failing to retrieve the current snapshot while saving a collaboration database</li>
  <li><strong>Fix</strong>: Fixed default path for <code class="language-plaintext highlighter-rouge">Create Type Archive</code> dialog when used with a project file</li>
  <li><strong>Fix</strong>: Fixed hang when checking floating license validity while unable to reach the Enterprise server</li>
  <li><strong>Fix</strong>: Fixed minor issues in the collaboration Python API</li>
  <li><strong>Fix</strong>: Fixed persistent <code class="language-plaintext highlighter-rouge">User Positions</code> errors</li>
  <li><strong>Fix</strong>: Fixed save dialog proposing the container name instead of the entry name for container files in projects</li>
  <li><strong>Fix</strong>: Fixed spurious crashes caused by unexpected WebSocket connection lifetime issues in collaboration</li>
  <li><strong>Fix</strong>: Fixed stale display name and virtual path information when saving a file</li>
</ul>

<h2 id="api">API</h2>

<ul>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/dd31558a0a1600342da23e2d0745be01ad19202b"><code class="language-plaintext highlighter-rouge">get_metadata()</code></a> method to <code class="language-plaintext highlighter-rouge">BinaryView</code>, <code class="language-plaintext highlighter-rouge">Function</code>, and <code class="language-plaintext highlighter-rouge">Project</code>, and made <code class="language-plaintext highlighter-rouge">query_metadata()</code> raise <code class="language-plaintext highlighter-rouge">KeyError</code> consistently</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/6f4404c36f765714b7474774cc81dc4bf329ee4f"><code class="language-plaintext highlighter-rouge">mutex</code> and <code class="language-plaintext highlighter-rouge">recursive_mutex</code></a> to <code class="language-plaintext highlighter-rouge">bn::base</code>, using <code class="language-plaintext highlighter-rouge">os_unfair_lock</code> on Apple platforms</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/efb7b798391b526bf7d6a29b6f87e8d95ee35d50"><code class="language-plaintext highlighter-rouge">TransformSession</code></a><a href="https://github.com/Vector35/binaryninja-api/commit/efb7b798391b526bf7d6a29b6f87e8d95ee35d50"> constructor</a> that adopts an existing <code class="language-plaintext highlighter-rouge">TransformContext</code></li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/d0eec62d6df0edbbb76dfeac58879797e90a8594">global plugin command type</a> for registering plugins available outside the context of a binary view</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/1477644130363181529308369212747957500371"><code class="language-plaintext highlighter-rouge">QualifiedName.separator</code></a> property to the Python API</li>
  <li><strong>Feature</strong>: Added a <a href="https://github.com/Vector35/binaryninja-api/commit/ddd7aa4e7cd5a1aa07a16c3895d1f91ebf49347b">hook for <code class="language-plaintext highlighter-rouge">BinaryView</code> subclasses</a> to run code after snapshot data is applied</li>
  <li><strong>Feature</strong>: Added missing <a href="https://github.com/Vector35/binaryninja-api/commit/5006d2cc099934b716f2474885fde5114225e438"><code class="language-plaintext highlighter-rouge">LowLevelILFunction::AddOverFlow</code></a> API</li>
  <li><strong>Feature</strong>: Added support for <a href="https://github.com/Vector35/binaryninja-api/commit/e2e420c91147f2a83cf59b37c973f57e209ef67a">calling conventions to specify required registers</a> for heuristic calling convention detection</li>
  <li><strong>Feature</strong>: Added support for <a href="https://github.com/Vector35/binaryninja-api/commit/43bb35136369ef11f2ef1f62b36a80bccb4eb4be">ephemeral session-time settings for <code class="language-plaintext highlighter-rouge">TransformSession</code></a></li>
  <li><strong>Feature</strong>: Exposed <a href="https://github.com/Vector35/binaryninja-api/commit/b8fdf800de345f93b2e68713d14bac425a62feb3"><code class="language-plaintext highlighter-rouge">BNDetectSearchMode</code></a> to the Python API for search mode testing</li>
  <li><strong>Feature</strong>: Introduced an <a href="https://github.com/Vector35/binaryninja-api/commit/540fca65afaff35343a938b86596b21f2e16b48d">RAII type for managing bulk symbol modifications</a> to simplify batched symbol updates</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/9c2a45b7b78742b0cfe0a8599b8fdbf1d24533d3"><code class="language-plaintext highlighter-rouge">TypeLibrary.remove_named_object</code> and <code class="language-plaintext highlighter-rouge">TypeLibrary.remove_named_type</code></a> to the Python API</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/8e9fd28ab887ce63a04db50f9b82a35a81996748">API to remove data from type libraries</a>, useful when relocating information between type libraries before finalization</li>
  <li><strong>Feature</strong>: Added <code class="language-plaintext highlighter-rouge">GetNamedTypeSource</code> API to type libraries</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/3520262824637979418554656607433424896809"><code class="language-plaintext highlighter-rouge">TypeLibrary::Register</code></a> to allow loading type libraries programmatically from scripts</li>
  <li><strong>Feature</strong>: Added missing <a href="https://github.com/Vector35/binaryninja-api/commit/8d5c0136c609564739527a528b9c4d9a6d6721ba"><code class="language-plaintext highlighter-rouge">TypeLibrary.duplicate</code></a> API to Python bindings</li>
  <li><strong>Improvement</strong>: Allow <a href="https://github.com/Vector35/binaryninja-api/commit/b765ffd736ecbfbb7c19b7e166a021ac46a9eeb8">decompressing standalone <code class="language-plaintext highlighter-rouge">TypeLibrary</code> objects</a> without requiring them to be written to disk first</li>
  <li><strong>Improvement</strong>: Updated <a href="https://github.com/Vector35/binaryninja-api/commit/13b9cb082d06784ab0d873db420dbd633c0660a3">function signatures of some type library APIs</a> in Python</li>
  <li><strong>Improvement</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/45ecf56486c5c6c29290d39978fbb46cab337e08"><code class="language-plaintext highlighter-rouge">BN_DEPRECATED</code></a><a href="https://github.com/Vector35/binaryninja-api/commit/45ecf56486c5c6c29290d39978fbb46cab337e08"> macro</a> to annotate deprecated C++ APIs with compiler warnings</li>
  <li><strong>Improvement</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/4e2d29352e8c24a2327300c5aeb71bad22a8e93a"><code class="language-plaintext highlighter-rouge">ProjectFile</code></a> type annotation to the Python <code class="language-plaintext highlighter-rouge">load</code> function</li>
  <li><strong>Improvement</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/f327d9565f49b047d38bc1a7583e5f4e3776261a"><code class="language-plaintext highlighter-rouge">SegmentInfo</code> and <code class="language-plaintext highlighter-rouge">SectionInfo</code></a> dataclasses and helper functions to make <code class="language-plaintext highlighter-rouge">add_user_segment</code>, <code class="language-plaintext highlighter-rouge">add_auto_segment</code>, and section APIs more Pythonic</li>
  <li><strong>Improvement</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/4b9edd0e5a7d9c4083ead51199ddbc629dc4154f"><code class="language-plaintext highlighter-rouge">VariableList::updateCrossReferences</code></a> declaration to the API</li>
  <li><strong>Improvement</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/6e50ceda4e65e5952e59449fad4953ea6c5aaf37">control over which address is used for instructions created when inlining during analysis</a></li>
  <li><strong>Improvement</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/a357da93100413a75bf0207e3cbd74bac3b54502">session settings override support to the <code class="language-plaintext highlighter-rouge">Transform</code> system</a> and improved documentation</li>
  <li><strong>Improvement</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/c86c641c720fbcd4ae9c99eb084ff565a53659c5">setters for <code class="language-plaintext highlighter-rouge">NamedTypeReferenceBuilder</code> properties</a> in the Python API</li>
  <li><strong>Improvement</strong>: Added <code class="language-plaintext highlighter-rouge">[[nodiscard]]</code> attribute to <a href="https://github.com/Vector35/binaryninja-api/commit/9ca4a08fbeabc22bed721ab522cf0a7dc4484a9f"><code class="language-plaintext highlighter-rouge">Structure</code>/<code class="language-plaintext highlighter-rouge">StructureBuilder</code> <code class="language-plaintext highlighter-rouge">GetMemberByName</code>/<code class="language-plaintext highlighter-rouge">GetMemberByOffset</code></a> to catch ignored return values at compile time</li>
  <li><strong>Improvement</strong>: Added <code class="language-plaintext highlighter-rouge">ForEachField</code> APIs to reduce copying of structure members</li>
  <li><strong>Improvement</strong>: Added support for <a href="https://github.com/Vector35/binaryninja-api/commit/3afe0f178f75f2f918cd9d418162dfce3a692337"><code class="language-plaintext highlighter-rouge">MLIL_SEPARATE_PARAM_LIST</code> and <code class="language-plaintext highlighter-rouge">MLIL_SHARED_PARAM_SLOT</code></a> in Python <code class="language-plaintext highlighter-rouge">copy_expr_to</code></li>
  <li><strong>Improvement</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/4277063091481910510752532405206398473989">type hints to <code class="language-plaintext highlighter-rouge">Architecture</code> flags fields</a> in the Python API</li>
  <li><strong>Improvement</strong>: Allow <a href="https://github.com/Vector35/binaryninja-api/commit/41497526378568c17c4340f6a523a696920c2d1a">overriding the IL source location</a> used by <code class="language-plaintext highlighter-rouge">ILInstruction::CopyTo</code></li>
  <li><strong>Improvement</strong>: Allows <a href="https://github.com/Vector35/binaryninja-api/commit/9154638116563015530687570074923214922938">flexible user plugin install location</a> via a CMake cache variable</li>
  <li><strong>Improvement</strong>: Enhanced <a href="https://github.com/Vector35/binaryninja-api/commit/6b57ef1d2c82d263655364588546e6211b0a99a8"><code class="language-plaintext highlighter-rouge">MemoryMap</code></a> bindings and added support to re-enable disabled regions in the UI</li>
  <li><strong>Improvement</strong>: Improved <code class="language-plaintext highlighter-rouge">Confidence&lt;T&gt;</code> move semantics to avoid unnecessary copies and reference count churn</li>
  <li><strong>Improvement</strong>: Improved performance of <a href="https://github.com/Vector35/binaryninja-api/commit/2448131059638409902821451115872036230328"><code class="language-plaintext highlighter-rouge">canMakeString</code></a></li>
  <li><strong>Improvement</strong>: Improved Python API for architectures and lifting</li>
  <li><strong>Improvement</strong>: Specified <a href="https://github.com/Vector35/binaryninja-api/commit/290bbcf333679ffa057d57d1b540608e3bec8ada">fixed underlying types for core-exposed enums</a>, shrinking several widely-used enums from 4 bytes to 1 byte</li>
  <li><strong>Improvement</strong>: Updated <a href="https://github.com/Vector35/binaryninja-api/commit/9644957532200715212384234845909260023279"><code class="language-plaintext highlighter-rouge">QualifiedName</code></a><a href="https://github.com/Vector35/binaryninja-api/commit/9644957532200715212384234845909260023279"> constructor</a> to accept a separator parameter</li>
  <li><strong>Improvement</strong>: Updated <a href="https://github.com/Vector35/binaryninja-api/commit/9397116241069777614336493120489779020689">Python API generator</a> to detect flag enums and emit <code class="language-plaintext highlighter-rouge">IntFlag</code> instead of <code class="language-plaintext highlighter-rouge">IntEnum</code></li>
  <li><strong>Improvement</strong>: Use <a href="https://github.com/Vector35/binaryninja-api/commit/95b849d05d05ae9e55eb839508536d5af314d331"><code class="language-plaintext highlighter-rouge">bn::base::function_ref</code></a> instead of <code class="language-plaintext highlighter-rouge">std::function</code> for non-stored callback parameters to reduce overhead</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/9601e9b1e5bfbccfdf79e157ec961affb4c9f2fa"><code class="language-plaintext highlighter-rouge">BinaryView.get_modification</code></a> failing when passing a length argument</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/c425acdb51f6b1dfcfd6e5ff56a4c3967507ccba"><code class="language-plaintext highlighter-rouge">LogTrace</code></a> <code class="language-plaintext highlighter-rouge">*FV</code>/<code class="language-plaintext highlighter-rouge">*F</code> variants to respect the <code class="language-plaintext highlighter-rouge">BN_ENABLE_LOG_TRACE</code> compile guard instead of unconditionally calling <code class="language-plaintext highlighter-rouge">fmt::vformat</code></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/da19d7e633872ad1c4ba5155e714062ba5c8e5ae"><code class="language-plaintext highlighter-rouge">TypeError</code> when slicing <code class="language-plaintext highlighter-rouge">FunctionList</code>/<code class="language-plaintext highlighter-rouge">BasicBlockList</code></a> with <code class="language-plaintext highlighter-rouge">[:]</code>, <code class="language-plaintext highlighter-rouge">[n:]</code>, or <code class="language-plaintext highlighter-rouge">[:n]</code></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/570a01aa6c9a3299ce30f04af89b3f01e96aebe4">crash in <code class="language-plaintext highlighter-rouge">show_message_box</code></a> when <code class="language-plaintext highlighter-rouge">description</code> is <code class="language-plaintext highlighter-rouge">None</code> in Python</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/695a94cdd9bd5e886ee82da60ebc5ffca5972fcb">GIL deadlock in <code class="language-plaintext highlighter-rouge">QueueGenerator</code> search APIs</a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/e7bbb5129fd032310b2e2f710ce83945c03f5b13">handling of <code class="language-plaintext highlighter-rouge">None</code> cases when empty strings are returned from core</a> and corrected associated <code class="language-plaintext highlighter-rouge">coreversion</code> usage</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/ca894f202609c8d27ba14ea1f200523e1ba7ba74">incorrect type hint and null string handling</a> in the API</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/ed0f3b1b8593f6b76fbb64c53a0885073c1c1979">many compiler warnings</a> when building with GCC 15.2</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/157045084b8938d02811f100f7b236685472658c">slice handling in <code class="language-plaintext highlighter-rouge">TagList</code></a> to match <code class="language-plaintext highlighter-rouge">FunctionList</code>/<code class="language-plaintext highlighter-rouge">BasicBlockList</code> behavior</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/5085389951883837291292944036914480410535"><code class="language-plaintext highlighter-rouge">BinaryView</code></a><a href="https://github.com/Vector35/binaryninja-api/commit/5085389951883837291292944036914480410535"> types</a> in Python API</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/6898277643046680846138467766554534807928"><code class="language-plaintext highlighter-rouge">CallingConvention.get_incoming_flag_value</code></a> in the Python API</li>
  <li><strong>Fix</strong>: Fixed <code class="language-plaintext highlighter-rouge">CoreVersionInfo</code> API and added unit tests</li>
  <li><strong>Fix</strong>: Fixed <code class="language-plaintext highlighter-rouge">Function::StoreMetadata</code> not marking the function as changed, ensuring dependent analysis is properly invalidated</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/5730756389247485689220739604918825879535"><code class="language-plaintext highlighter-rouge">get_flag_write_low_level_il</code></a> to properly extract LLIL flags in the Python API</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/4793365011024408570534500752595720571911"><code class="language-plaintext highlighter-rouge">Platform.view_init</code></a> passing the cffi object instead of the API object</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/5999964098498384717717737078276067473007"><code class="language-plaintext highlighter-rouge">QualifiedName</code></a> join from FFI and added <code class="language-plaintext highlighter-rouge">NameSpace</code> join support</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/4399766500542074600721693015367320395719">covariant user list types</a> in Python API</li>
  <li><strong>Fix</strong>: Fixed crashes when passing null to demangle APIs</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/6728415172553838701009676202433153533565">enums not being cast to their types</a> in the Python bindings generator</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/0238488101541494701887783104734147250961">generator handling of sub-4-byte signed enums with negative members</a> (affected <code class="language-plaintext highlighter-rouge">InvalidILViewType</code>)</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/1897812185980436930607387186292384077778">LLIL <code class="language-plaintext highlighter-rouge">flags</code> parameter type annotation</a> to correctly reflect flag writes rather than flags</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/8053519294751616998558811461876233782245">missed mismatch detection for <code class="language-plaintext highlighter-rouge">flag_name</code></a> in Python API</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/1530770981627436259078461823272722710609">overriding <code class="language-plaintext highlighter-rouge">Architecture.assemble</code></a> in Python subclasses being broken</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/1893495114355955459518559551893143577868">Python <code class="language-plaintext highlighter-rouge">QName</code> separator method</a> to use the correct name <code class="language-plaintext highlighter-rouge">join</code> to match the C++ API</li>
  <li><strong>Fix</strong>: Fixed Python type issues and updated tests to account for new field in <code class="language-plaintext highlighter-rouge">QualifiedName</code> struct</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/2099579041340399246976046395863741933136">use-after-free bug in <code class="language-plaintext highlighter-rouge">TypeBuilder.handle</code></a> where the underlying object was deleted before the handle was used</li>
  <li><strong>Fix</strong>: Relaxed <a href="https://github.com/Vector35/binaryninja-api/commit/8629952448196921178343893775948845506257">type constraints on children passed into type factories</a> in the Python API</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/cbc66f931da1046b3980c2c7c6b64c2f2ac358e2">operand list iterators being invalidated</a> when appending new instructions by storing offsets instead of pointers</li>
</ul>

<h2 id="rust-api">Rust API</h2>

<ul>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/c9b43e1825977c3e6f32fc32938a963c3b3a5b17"><code class="language-plaintext highlighter-rouge">address_comments</code></a> to <code class="language-plaintext highlighter-rouge">BinaryViewExt</code> in the Rust API</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/c68f8d48afb9b3e6cdac363c8a578a051ad6e21d"><code class="language-plaintext highlighter-rouge">BinaryViewExt::tags_all_scopes</code>, <code class="language-plaintext highlighter-rouge">tag_types</code>, and <code class="language-plaintext highlighter-rouge">tags_by_type</code></a> to the Rust API</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/13e7701c86c284513091a93f37a68d320073dc41"><code class="language-plaintext highlighter-rouge">BinaryViewExt::type_libraries</code></a> to the Rust API</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/ddf9fb555f97a5a009d9c1ea2aa1a76e6435726e"><code class="language-plaintext highlighter-rouge">From&lt;BnString&gt;</code> impl for <code class="language-plaintext highlighter-rouge">QualifiedName</code></a> to simplify conversions</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/906de8cf124a6cc74d28c1f82ea9b4883b97efde"><code class="language-plaintext highlighter-rouge">Function::defined_symbol</code></a> to retrieve a function’s symbol only when it is explicitly defined</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/5872ea35017892cd15e3bd1adb500eb9cd02c3c5"><code class="language-plaintext highlighter-rouge">load_project_file</code> and <code class="language-plaintext highlighter-rouge">load_project_file_with_progress</code></a> to open project-linked files and avoid detached binary views</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/59b73aa1834d5f558595a888411c70a4fac31a3f"><code class="language-plaintext highlighter-rouge">LowLevelILSSARegister</code></a> type to the Rust API</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/271fff5e07edd7abcbbc8afbbd5e7e3fd85d69e4"><code class="language-plaintext highlighter-rouge">OwnedBackgroundTaskGuard</code></a> for automatically finishing background tasks via RAII</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/bc5e0b8ba9520d560bb07ee298047c7880b879ff"><code class="language-plaintext highlighter-rouge">Platform::address_size</code></a> to the Rust API</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/d0c590401d28d949b825cab1462549e41c1046af"><code class="language-plaintext highlighter-rouge">Symbol::ordinal</code></a> to the Rust API</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/1f98e7ca7cce35ae4c2b4741f33e9892dd695534"><code class="language-plaintext highlighter-rouge">TypeBuilder::function</code> and <code class="language-plaintext highlighter-rouge">TypeBuilder::function_with_opts</code></a> to the Rust API for constructing function types</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/2ccba5081488225007810f232dbe063512ebc4bd"><code class="language-plaintext highlighter-rouge">TypeBuilder::set_signed</code></a> to the Rust API</li>
  <li><strong>Feature</strong>: Implemented <a href="https://github.com/Vector35/binaryninja-api/commit/8e4bfe3f71232ab6e8332d4c7903290a1396f9b9">data notification API</a> for Rust bindings</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/c980b77666bba9e4480c44de72cc8de0ca10c8e4"><code class="language-plaintext highlighter-rouge">TypeLibrary::remove_named_object</code> and <code class="language-plaintext highlighter-rouge">TypeLibrary::remove_named_type</code></a> to the Rust API</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/ed7b6697e636bb654b351aa159f648c8591f0ac3">APIs to retrieve type archives for a binary view</a> in Rust</li>
  <li><strong>Improvement</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/7a7f9f07f16922cfbf744ed428ac482b988adf27">miscellaneous <code class="language-plaintext highlighter-rouge">TypeLibrary</code> API improvements</a> to the Rust bindings</li>
  <li><strong>Improvement</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/13379a1f5edbebf2dbf0008fb8813dcca82a3294">more type library examples</a> for the Rust API</li>
  <li><strong>Improvement</strong>: Added dedicated <a href="https://github.com/Vector35/binaryninja-api/commit/040976497749aaa02d54e125ce2b34300213bfb0"><code class="language-plaintext highlighter-rouge">TypeArchiveId</code></a> type to prevent ID type confusion in the type archive API</li>
  <li><strong>Improvement</strong>: Implemented <a href="https://github.com/Vector35/binaryninja-api/commit/826bd1a2da1077e5f5c55afec9112d4790ed62e0"><code class="language-plaintext highlighter-rouge">Send</code> and <code class="language-plaintext highlighter-rouge">Sync</code></a> for <code class="language-plaintext highlighter-rouge">TypeLibrary</code> to enable safe cross-thread usage</li>
  <li><strong>Improvement</strong>: Improved <a href="https://github.com/Vector35/binaryninja-api/commit/2e6637c9ce4fc6a001e7ccc1243c0238edb24fa6">API surrounding binary view type libraries</a> in the Rust bindings</li>
  <li><strong>Improvement</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/bc195c1c21da0400a1a1dde1fcdde45d687e666f">miscellaneous documentation</a> to the Rust API</li>
  <li><strong>Improvement</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/fcebb0e1c6723fa0d8039ba098717550e24deea6">more architecture module documentation and misc cleanup</a> to the Rust API</li>
  <li><strong>Improvement</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/69ef5923e93d75f1d7c2bf06dfac8ab0235c6d63">setters for creating NTR references</a> in the Rust API</li>
  <li><strong>Improvement</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/209674781d2bc75897bc158fff8b48e4ddee1691">top-level documentation</a> to the <code class="language-plaintext highlighter-rouge">tracing</code> and <code class="language-plaintext highlighter-rouge">logger</code> modules</li>
  <li><strong>Improvement</strong>: Implemented <a href="https://github.com/Vector35/binaryninja-api/commit/f9d2e6f1d605d7d1a1a227b4fb1d367693bc0742"><code class="language-plaintext highlighter-rouge">BinaryViewEventHandler</code></a> for <code class="language-plaintext highlighter-rouge">Fn(&amp;BinaryView)</code>, allowing closures to be passed directly to the register function</li>
  <li><strong>Improvement</strong>: Implemented <code class="language-plaintext highlighter-rouge">Debug</code> for <a href="https://github.com/Vector35/binaryninja-api/commit/0f919f8fa8043892e4f723d0aa382fa7fc044374"><code class="language-plaintext highlighter-rouge">RemoteProject</code></a>, <a href="https://github.com/Vector35/binaryninja-api/commit/d61826e8fbe3580c762f7f317f69201bce3710ad"><code class="language-plaintext highlighter-rouge">RemoteFolder</code></a>, and <a href="https://github.com/Vector35/binaryninja-api/commit/ef967ae27d303bbb6f3a5ea9ff7b1bdfcf6c2637"><code class="language-plaintext highlighter-rouge">BinaryViewType</code></a></li>
  <li><strong>Improvement</strong>: Implemented <code class="language-plaintext highlighter-rouge">Display</code> for <a href="https://github.com/Vector35/binaryninja-api/commit/393d6dda437d848f51efacceb8618b937d9f08f3"><code class="language-plaintext highlighter-rouge">Symbol</code></a>, <a href="https://github.com/Vector35/binaryninja-api/commit/ae02e4cfe187752766a1137b2ce87a5642e89c44"><code class="language-plaintext highlighter-rouge">FileMetadata</code></a>, and <a href="https://github.com/Vector35/binaryninja-api/commit/c3b40624916b3f75e9941158b43972e78e3f2a98"><code class="language-plaintext highlighter-rouge">VersionInfo</code></a></li>
  <li><strong>Improvement</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/34e93635fd0df131f92f0dcaa8a061648148e40d"><code class="language-plaintext highlighter-rouge">PartialEq</code>, <code class="language-plaintext highlighter-rouge">Eq</code>, and <code class="language-plaintext highlighter-rouge">Hash</code></a> for <a href="https://github.com/Vector35/binaryninja-api/commit/34e93635fd0df131f92f0dcaa8a061648148e40d"><code class="language-plaintext highlighter-rouge">ProjectFile</code></a> and <a href="https://github.com/Vector35/binaryninja-api/commit/a40a300cce8a798200562e9d4515116360dbd0b1"><code class="language-plaintext highlighter-rouge">Project</code></a></li>
  <li><strong>Improvement</strong>: Implemented <code class="language-plaintext highlighter-rouge">Send</code> and <code class="language-plaintext highlighter-rouge">Sync</code> for <a href="https://github.com/Vector35/binaryninja-api/commit/0d5fc76a872a2c570def2fb292cf1b988fb70603"><code class="language-plaintext highlighter-rouge">RemoteFolder</code></a>, <a href="https://github.com/Vector35/binaryninja-api/commit/75f4b939c656cc53ab7ecfb8b24af7fcb6961d10"><code class="language-plaintext highlighter-rouge">CoreLanguageRepresentationFunctionType</code></a>, <a href="https://github.com/Vector35/binaryninja-api/commit/a096d1dc942ee22826087bfd12caf3a209df24fd"><code class="language-plaintext highlighter-rouge">RemoteProject</code></a>, and <a href="https://github.com/Vector35/binaryninja-api/commit/d4a19d793d6d080081f02ff16ac3db3eacc03ace"><code class="language-plaintext highlighter-rouge">RemoteFile</code></a></li>
  <li><strong>Improvement</strong>: Made <a href="https://github.com/Vector35/binaryninja-api/commit/c8d44056b60c0e790da58fc1cfc22a77a4099023"><code class="language-plaintext highlighter-rouge">InstructionTextToken</code></a> field <code class="language-plaintext highlighter-rouge">expr_index</code> optional via <code class="language-plaintext highlighter-rouge">Option</code> type</li>
  <li><strong>Improvement</strong>: Refactored <a href="https://github.com/Vector35/binaryninja-api/commit/25607f00539187e0834f5c6bbad9eaf1586a6fa7"><code class="language-plaintext highlighter-rouge">AnalysisProgress</code></a> returned from <code class="language-plaintext highlighter-rouge">BinaryViewExt::analysis_progress</code></li>
  <li><strong>Improvement</strong>: Refactored <a href="https://github.com/Vector35/binaryninja-api/commit/c1dbea197a6ba7e3d008e01c8169f5c3702151ea"><code class="language-plaintext highlighter-rouge">FileMetadata</code></a> to rename and retype <code class="language-plaintext highlighter-rouge">filename</code> and require it to be set at construction time</li>
  <li><strong>Improvement</strong>: Removed <a href="https://github.com/Vector35/binaryninja-api/commit/2c7ba495a6c1d8b3639b74334b0cdd1809af807e"><code class="language-plaintext highlighter-rouge">UnusedRegisterStackInfo</code></a> and updated architecture documentation in the Rust API</li>
  <li><strong>Improvement</strong>: Removed redundant <a href="https://github.com/Vector35/binaryninja-api/commit/7090d904513c3e80321bb6a8aba9c3b37d809bac"><code class="language-plaintext highlighter-rouge">ArchAndAddr</code></a> type in favor of <code class="language-plaintext highlighter-rouge">Location</code></li>
  <li><strong>Improvement</strong>: Replaced <a href="https://github.com/Vector35/binaryninja-api/commit/168a3fd34824adc9c6a606cd144219701f15cccf"><code class="language-plaintext highlighter-rouge">log</code></a> with <code class="language-plaintext highlighter-rouge">tracing</code> for logging in the Rust API</li>
  <li><strong>Improvement</strong>: Restructured <a href="https://github.com/Vector35/binaryninja-api/commit/ca0e32efb1e5b9eba157e9fd2eef178d9367c578">type APIs into a <code class="language-plaintext highlighter-rouge">types</code> module</a> for improved discoverability and documentation</li>
  <li><strong>Improvement</strong>: Updated <a href="https://github.com/Vector35/binaryninja-api/commit/f06a8008a1f44fde0e77c693620d5128a6b8edc9"><code class="language-plaintext highlighter-rouge">TagReference</code></a> to optionally accept architecture and function parameters</li>
  <li><strong>Improvement</strong>: Updated <a href="https://github.com/Vector35/binaryninja-api/commit/b9e1d7be12e6e9ff41cced5aabf1b54109aade3c"><code class="language-plaintext highlighter-rouge">TypeBuilder::named_type</code></a> to accept <code class="language-plaintext highlighter-rouge">type_reference</code> by reference instead of by value</li>
  <li><strong>Improvement</strong>: Updated <a href="https://github.com/Vector35/binaryninja-api/commit/e45d8e4324cdc1fb8ed2b60113c1af9e7db499de"><code class="language-plaintext highlighter-rouge">TypeParser</code></a> to use <code class="language-plaintext highlighter-rouge">PathBuf</code> instead of <code class="language-plaintext highlighter-rouge">String</code> for include directory parameters</li>
  <li><strong>Improvement</strong>: Updated <a href="https://github.com/Vector35/binaryninja-api/commit/2e5b893b79e053dbacd8a72cc900d1af1d825041">debug info functions</a> to return <code class="language-plaintext highlighter-rouge">Array</code> types for more consistent Rust API patterns</li>
  <li><strong>Fix</strong>: Added <a href="https://github.com/Vector35/binaryninja-api/commit/4bfb2b64459de2d243ff29268c1991824ae3e11a">precondition check</a> to ensure metadata is pulled before pulling remote projects</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/ff58143ff7794d7251f9182294dd25bd4cbe15eb"><code class="language-plaintext highlighter-rouge">load_view_with_progress</code></a> when <code class="language-plaintext highlighter-rouge">options</code> is <code class="language-plaintext highlighter-rouge">None</code></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/f325aa7b6026a1daef84931baeb1f50d7da10c10"><code class="language-plaintext highlighter-rouge">PartialEq</code> and <code class="language-plaintext highlighter-rouge">Hash</code> impls for <code class="language-plaintext highlighter-rouge">FileMetadata</code></a> to use the unique <code class="language-plaintext highlighter-rouge">session_id</code> for comparisons and hashing</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/742370bc6e18b1e3e3b42eee4fc5367dc336b785"><code class="language-plaintext highlighter-rouge">QualifiedName::default()</code></a> incorrectly creating a <code class="language-plaintext highlighter-rouge">QualifiedName</code> with an empty separator</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/0ec8e7d31dcd5c38498ac473db46e3b55883edd2">crash when calling <code class="language-plaintext highlighter-rouge">LowLevelILFunction::generate_ssa_form</code></a> without an owner function</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/b7af0a9b02319aba2875633e4348f459035a4b79">double free in <code class="language-plaintext highlighter-rouge">analysis_info</code></a> with function refs and added string reader helpers</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/dbd54d67a6d523f64615f653d82d8224cd09870a">lifetime management of <code class="language-plaintext highlighter-rouge">WebsocketClientCallback</code> objects</a> in the Rust API</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/e699fec29106d46303ef4bcb464a768e23bb28ea">memory leak in <code class="language-plaintext highlighter-rouge">Function::guided_source_blocks</code></a> where <code class="language-plaintext highlighter-rouge">BNFreeArchitectureAndAddressList</code> was not called</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/d64f392bc90d6057ef6df62229b0ef6d354a67a1">unbalanced ref returned in <code class="language-plaintext highlighter-rouge">RemoteFile::core_file</code></a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/a0204330869723c10ac145a257ff02024b8add3d">undefined behavior when passing include directories to <code class="language-plaintext highlighter-rouge">CoreTypeParser</code></a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/83839571880d248d1b07c8eed4d1ec12d074bfd9">untyped <code class="language-plaintext highlighter-rouge">expr_idx</code> within MLIL <code class="language-plaintext highlighter-rouge">ILReferenceSource</code></a> in the Rust API</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/1b552d72eff547ef53a4e9af9a95382f9031f681"><code class="language-plaintext highlighter-rouge">BinaryViewExt::address_comments</code></a> memory leak and refactored implementation</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/bfbb878c05220e1697aa550a23ad59911e546c17"><code class="language-plaintext highlighter-rouge">OwnedBackgroundTaskGuard</code></a> to not require mutable <code class="language-plaintext highlighter-rouge">self</code></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/binaryninja-api/commit/24ad42106cc77fe4e7d28f9137aa084fdfe90c72">undefined behavior in basic block analysis context out parameters</a> in the Rust API</li>
  <li><strong>Deprecation</strong>: <a href="https://github.com/Vector35/binaryninja-api/commit/315cd66b948e4a960d09050520b5d40fb33e5fb3">Removed deprecated</a> MLIL functions from the Rust API</li>
</ul>

<h2 id="debugger-1">Debugger</h2>

<ul>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/debugger/commit/42d75506e93bb66aad59d34c50e1b2801ad92b6b"><code class="language-plaintext highlighter-rouge">NextMemoryAccess</code>/<code class="language-plaintext highlighter-rouge">PrevMemoryAccess</code></a> API and UI for TTD (Time Travel Debugging)</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/debugger/commit/5ee0d738c96134e0bcc0dcf71284d1f415c8f1ea">container file detection and extraction</a> support to the debugger</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/debugger/commit/02692b56c73c4c7d980fe6cb05d107788a4d32ed">execution count display</a> for instructions in the code coverage analysis render layer</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/debugger/commit/b72e83b195e3e211e6e36d8d99afa18c8f99d55b">manual rebasing support</a> via <code class="language-plaintext highlighter-rouge">debugger.autoRebase</code> setting and a new Rebase to Remote Base action</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/debugger/commit/f81b54ae76d7b5db7f8a5bb889a98448f6a04bdd">module names to the expression parser</a> for address resolution</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/debugger/commit/7ecb5ede6a2120de01b29fbc4fe4b5479f589eeb">process list viewing and selection</a> for the esReven adapter</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/debugger/commit/7736afacd9d81ce284674f60a1632b6a771bef6e">setting to disable LLDB auto-install</a> during remote debugging, addressing an issue where LLDB would delete the debugged binary</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/debugger/commit/d55e7bfd56dc81b75294d8ecc63e1f3c570d3b41">support for bookmarking timestamps in TTD</a> sessions</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/debugger/commit/67941ecce2c611eb6d1d6c292b85e065676931a9">time range filter option for TTD code coverage analysis</a> to narrow coverage results to a specific execution window</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/debugger/commit/3c87ea2ee3b5b8fccf9dbadea6eca52d2a3adb10">TTD attach to running process</a> support</li>
  <li><strong>Feature</strong>: Added <a href="https://github.com/Vector35/debugger/commit/3822d2fc2914c7d59a2c28cc05a2a00097c0307f">TTD timestamp history navigation</a> (back/forward) to allow stepping through recorded stop positions</li>
  <li><strong>Feature</strong>: Enabled <a href="https://github.com/Vector35/debugger/commit/f4c7e1c7a7adf7c250d5bd505a0a52f2e698ffb6">TTD menu and widgets</a> on Linux and macOS</li>
  <li><strong>Feature</strong>: Implemented <a href="https://github.com/Vector35/debugger/commit/0e0dc2a38ee530533ce2ee7ec5669143fa108c8b"><code class="language-plaintext highlighter-rouge">GetCurrentTTDPosition</code> and <code class="language-plaintext highlighter-rouge">SetTTDPosition</code></a> for the esReven adapter using <code class="language-plaintext highlighter-rouge">rvn:get-current-transition</code> and <code class="language-plaintext highlighter-rouge">rvn:set-current-transition</code></li>
  <li><strong>Feature</strong>: Implemented <a href="https://github.com/Vector35/debugger/commit/fdfba0e4d1e6448342ef2d59bb7a4aa312e07c8f"><code class="language-plaintext highlighter-rouge">GetThreadList</code> and <code class="language-plaintext highlighter-rouge">GetFramesOfThread</code></a> for the esReven adapter using the <code class="language-plaintext highlighter-rouge">rvn:list-threads</code> packet</li>
  <li><strong>Feature</strong>: Implemented <a href="https://github.com/Vector35/debugger/commit/cdb436abe736e3b313e8cdbd1ac38490a011d5da">TTD memory access queries</a> for the esReven adapter using <code class="language-plaintext highlighter-rouge">rvn:get-memory-accesses</code></li>
  <li><strong>Improvement</strong>: Added <a href="https://github.com/Vector35/debugger/commit/825f36b801ef5f46ccb1e60232ce8ec0a7c1ffe3">new icons for TTD back/forward controls</a></li>
  <li><strong>Improvement</strong>: Added <a href="https://github.com/Vector35/debugger/commit/850744dbcac40fb9a9a7a7d4992969c7408d1075">regex and case sensitivity options to <code class="language-plaintext highlighter-rouge">FilterEdit</code></a> in the debugger</li>
  <li><strong>Improvement</strong>: Added <a href="https://github.com/Vector35/debugger/commit/50a7e6d007544021afc7b0acaf7c421873bfa83d">row copy/paste support and multi-row selection</a> to the registers widget</li>
  <li><strong>Improvement</strong>: Added configurable <a href="https://github.com/Vector35/debugger/commit/cfb69b4e590b22d7631fab3723c0039185addc05"><code class="language-plaintext highlighter-rouge">ttd.maxSymbolsLimit</code></a> setting (default 50, 0 for no limit) for esReven TTD wildcard symbol lookups</li>
  <li><strong>Improvement</strong>: Improved <a href="https://github.com/Vector35/debugger/commit/aaba3d415385b3008d20212a9fbec2c00d0b1181">TTD widget UI</a> on macOS</li>
  <li><strong>Improvement</strong>: Improved <a href="https://github.com/Vector35/debugger/commit/abf72818b196b5df545adc89cfaca6131e84f1f0">WinDbg/TTD installation process</a> with quality-of-life enhancements</li>
  <li><strong>Improvement</strong>: Updated <a href="https://github.com/Vector35/debugger/commit/386ed9ed856f2251482a17187491423d953a1c58"><code class="language-plaintext highlighter-rouge">DebugBreakpoint.__repr__</code></a> to include the condition when set</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/debugger/commit/8186cfb09f6e9c4f05e94bda7e81ebdf0c729f18"><code class="language-plaintext highlighter-rouge">ParseGdbValue</code></a> to correctly handle vector/SIMD registers and unavailable values in GDB MI register output</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/debugger/commit/b8b213a1541619066ee0765968676eb789226d43">big-endian register parsing</a> in the GDB RSP adapter for PowerPC and other big-endian targets</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/debugger/commit/c7e0cf17d93d8a421e6013c69254437ef13dd916">concurrent access issue in <code class="language-plaintext highlighter-rouge">g_debuggerControllers</code></a> by replacing raw pointer management with thread-safe storage</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/debugger/commit/b31341154ae29da17c5512f2586c80aaad89767b">crash in uncaught exceptions thrown by code</a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/debugger/commit/9ee2355eb2b7e044a181126b7d7201bf9dc45afb">crash when attaching to a process</a> if <code class="language-plaintext highlighter-rouge">dbgeng</code> fails to initialize</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/debugger/commit/9c3d02488c29e676e034a7812eedfe9838689780">crash when connecting to QEMU-PPC targets</a> due to architecture string missing a hyphen after the colon</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/debugger/commit/8bc88f8d6a735c80f6756c70a55e8c0d16688795">multiple debugger bugs</a> including Python FFI mismatches, mutex leak, thread state issues, and double notification</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/debugger/commit/7047b5d2de076813da2c12e85fd19489252a8222">potential null pointer dereferences</a> when acquiring dynamic UI objects in the debugger</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/debugger/commit/5d3a23c1c6d505996acb983929a5589c30cc6d84">sorting in TTD event widget</a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/debugger/commit/75fc20ff1e46000e618dfc83681ef620a1dd627c">view not refreshing after TTD coverage analysis completes</a></li>
  <li><strong>Fix</strong>: Fixed delay-loading of Sentry to prevent <code class="language-plaintext highlighter-rouge">dbghelp.dll</code> from loading from System32 and breaking the <code class="language-plaintext highlighter-rouge">dbgeng</code> adapter</li>
  <li><strong>Fix</strong>: Fixed error when accessing <code class="language-plaintext highlighter-rouge">dbg.breakpoints</code></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/debugger/commit/2296ddb629d252c2838055a844008f383dd31910">conditional breakpoint evaluation when stepping onto a breakpoint</a> in LLDB</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/debugger/commit/613e6788f380dead60200629293e1c264aea4b43">crash when retrieving breakpoint condition</a></li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/debugger/commit/acf883e0dba8b99751d7ab835a5f0afb3fa29289">crash when toggling breakpoints</a> with the GDB MI adapter</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/debugger/commit/052dc6c1d2b98f4ff4f89d0acfc3226cd13a790e">TTD negotiation breaking regular debugging</a> in the GDB MI adapter</li>
  <li><strong>Fix</strong>: Fixed <a href="https://github.com/Vector35/debugger/commit/792e8249c6266e54fae4a5ca57e3e3aaec74c026">values wider than 8 bytes displaying as <code class="language-plaintext highlighter-rouge">0x0</code></a> in the TTD memory widget</li>
</ul>

<h2 id="documentation">Documentation</h2>

<ul>
  <li><strong>Improvement</strong>: Added <a href="https://docs.binary.ninja/guide/debugger/#addremove-hardware-breakpoints">documentation for hardware breakpoints</a></li>
  <li><strong>Improvement</strong>: Added <a href="https://docs.binary.ninja/dev/concepts.html#ui-elements">examples for <code class="language-plaintext highlighter-rouge">execute_</code> APIs</a></li>
  <li><strong>Improvement</strong>: Added <a href="https://docs.binary.ninja/about/privacy.html">explicit online privacy documentation</a> covering data collection and network usage</li>
  <li><strong>Improvement</strong>: Added <a href="https://docs.binary.ninja/dev/workflows.html">module workflow hello world example</a></li>
  <li><strong>Improvement</strong>: Added <a href="https://docs.binary.ninja/guide/troubleshooting.html#defender-causes-slow-startup">Windows Defender antivirus exception documentation</a></li>
  <li><strong>Improvement</strong>: Added <a href="https://docs.binary.ninja/guide/troubleshooting.html#miniconda-and-miniforge">Windows Python workaround documentation</a> for known compatibility issue</li>
  <li><strong>Improvement</strong>: Added <a href="https://docs.binary.ninja/guide/types/attributes.html#custom-attributes">docs for <code class="language-plaintext highlighter-rouge">__attr</code></a></li>
  <li><strong>Improvement</strong>: Reorganized <a href="https://docs.binary.ninja/dev/archplatform-disassembly.html">Quark documentation</a> into a dedicated section to improve readability</li>
  <li><strong>Improvement</strong>: Updated <a href="https://docs.binary.ninja/guide/debugger/#navigating-the-binary">docs for using module names in the expression parser</a></li>
  <li><strong>Improvement</strong>: Updated <a href="https://docs.binary.ninja/guide/debugger/dbgeng-ttd.html">TTD documentation</a> to cover new features</li>
  <li><strong>Improvement</strong>: Updated <a href="https://docs.binary.ninja/guide/migration/ghidra/ghidraimport.html">Ghidra import documentation</a> with minor tweaks and improved cross-references</li>
</ul>

<p>Despite the list of changes getting bigger with almost every release, it still doesn’t cover everything that’s happened! If you want to see even more details, check out our <a href="https://github.com/Vector35/binaryninja-api/milestone/29?closed=1">closed milestone</a> on GitHub.</p>]]></content><author><name>Jordan Wiens</name><email>jordan@vector35.com</email></author><category term="announcements" /><category term="stable" /><summary type="html"><![CDATA[For Binary Ninja 5.3, we’re bringing features and fixes across a number of areas. For improved interoperability, we’ve added Ghidra Export to the existing Ghidra Import code and have improved our IDB Import capability. For new architectures and platforms, we’ve added NDS32 to Ultimate, a new ILP32 ABI for AArch64, and a new set of APIs for “weird” architectures. And of course, we’ve made a number of improvements to the UI including a new Universal Mach-O loader UI, usability improvements to the container browser, and a new “super” command palette! Plus, changes to the debugger, enterprise features, new opt-in crash reporting to help us squash bugs faster, and so much more! Note: A second release (R2) with stability improvements and bug fixes is now available.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://binary.ninja/blog/images/5.3-release/jotunheim.jpg" /><media:content medium="image" url="https://binary.ninja/blog/images/5.3-release/jotunheim.jpg" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">Container Transforms: Working with Nested Binary Formats</title><link href="https://binary.ninja/2026/03/31/container-transforms.html" rel="alternate" type="text/html" title="Container Transforms: Working with Nested Binary Formats" /><published>2026-03-31T13:42:00+00:00</published><updated>2026-03-31T13:42:00+00:00</updated><id>https://binary.ninja/2026/03/31/container-transforms</id><content type="html" xml:base="https://binary.ninja/2026/03/31/container-transforms.html"><![CDATA[<p><img src="/blog/images/container/container.png" alt="Container Transforms &gt;" class="image max-height-300" /></p>

<p>Firmware analysis, malware triage, and embedded systems reverse engineering often require extracting files from nested container formats: TAR archives inside GZIP files, encrypted firmware wrapped in multiple compression layers, or password-protected ZIPs containing “infected” malware.</p>

<p>Manually peeling each layer with separate tools gets old fast.</p>

<p>Binary Ninja’s Container Transform system automates this workflow, handling detection, extraction, password management, and multi-layer nesting while preserving the structure and provenance of each stage.</p>

<!--more-->

<h2 id="the-nested-binary-challenge">The Nested Binary Challenge</h2>

<p>Consider analyzing an Apple firmware update:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>firmware.img4 (IMG4 container)
  └─ LZFSE compressed payload
      └─ Mach-O kernel
</code></pre></div></div>

<p>Traditionally you would:</p>

<ol>
  <li>Recognize the IMG4 format</li>
  <li>Extract the payload</li>
  <li>Identify and decompress LZFSE</li>
  <li>Finally load the Mach-O</li>
</ol>

<p>With Container Transforms, this entire chain resolves automatically during file load. Here’s the end result of this feature in action:</p>

<p><img src="/blog/images/container/machokernel.gif" alt="Opening a Mach-O kernel from an IMG4 firmware container" class="image" /></p>

<h2 id="the-real-problem-representation">The Real Problem: Representation</h2>

<p>This system began with a narrower feature: <em>support for memory regions that store decoded data</em>.</p>

<p>The initial impetus for this was performance-related (<a href="https://github.com/Vector35/binaryninja-api/issues/7234">GitHub issue #7234</a>). Decoded data flowing through the Undo buffer caused regressions because that system was designed for small user-driven edits, not large, derived byte streams.</p>

<p>But the deeper issue was not performance. It was representation itself.</p>

<p>Decoded data has:</p>

<ul>
  <li><strong>Provenance</strong>: how it was produced</li>
  <li><strong>Structure</strong>: which container or encoding it came from</li>
  <li><strong>Multiplicity</strong>: one input may produce many outputs</li>
</ul>

<p>Flattening derived data into a linear memory view discards that information.</p>

<p>What was missing was a proper way to model derived artifacts: data that exists because it was decoded, decompressed, or extracted from something else, possibly across multiple stages.</p>

<p>The Container Transform system models each step as a contextual transformation instead of mutating data in place. The result is a navigable tree of derived artifacts that preserves structure, metadata, and history without special cases.</p>

<h2 id="architectural-direction">Architectural Direction</h2>

<p>We considered several ways this could have been implemented:</p>

<ul>
  <li>A completely new subsystem for extracted data</li>
  <li>Representing each stage as a <a href="https://api.binary.ninja/binaryninja.binaryview-module.html#binaryninja.binaryview.BinaryView"><code class="language-plaintext highlighter-rouge">BinaryView</code></a></li>
  <li>Extending the existing Transform system</li>
</ul>

<p>Building a parallel subsystem could add unnecessary complexity. Modeling each stage as a <code class="language-plaintext highlighter-rouge">BinaryView</code> would have blurred the line between representation and analysis. A <code class="language-plaintext highlighter-rouge">BinaryView</code> implies analyzable program state, lifecycle semantics, and ownership that do not apply to intermediate decoding stages.</p>

<p>Instead, we leveraged our existing <a href="https://api.binary.ninja/binaryninja.transform-module.html#binaryninja.transform.Transform"><code class="language-plaintext highlighter-rouge">Transform</code></a> system and extended it with explicit contextual representation. Transforms now produce <em>context</em>, not just bytes. That distinction enables nested containers, multi-output transforms, automatic and interactive workflows, and a clean separation between extraction and analysis.</p>

<h2 id="what-are-container-transforms">What Are Container Transforms?</h2>

<p>Container transforms are specialized transforms that decode structured formats. Unlike simple encodings (Base64, Hex), container transforms can:</p>

<ol>
  <li><strong>Auto-detect</strong> formats using magic bytes or other signatures</li>
  <li><strong>Extract multiple outputs</strong> from a single input</li>
  <li><strong>Handle passwords and encryption</strong></li>
  <li><strong>Chain</strong> across nested formats</li>
  <li><strong>Preserve provenance</strong> information</li>
</ol>

<h3 id="mental-model-trees-not-pipelines">Mental Model: Trees, Not Pipelines</h3>

<pre><code class="language-mermaid">graph TD
    A["archive.tar.gz"] --&gt;|Gzip| B["archive.tar"]
    B --&gt;|Tar| C["README.md"]
    B --&gt;|Tar| D["firmware.img4"]
    B --&gt;|Tar| E["config.json"]
    D --&gt;|IMG4| F["LZFSE payload"]
    F --&gt;|LZFSE| G["Mach-O kernel"]
</code></pre>

<p>Container extraction forms a tree rather than a linear pipeline. Each node represents a transformation step; children represent derived artifacts. You can inspect intermediate layers instead of interacting only with a flattened final result.</p>

<p>Binary Ninja ships with detection-enabled transforms for:</p>

<ul>
  <li><strong>Compression</strong>: Gzip, Zlib, Bzip2, LZMA, LZ4 (Frame), Zstd, XZ, LZFSE</li>
  <li><strong>Archives</strong>: Zip, Tar, CPIO, AR, CaRT</li>
  <li><strong>Binary Containers</strong>: IMG4, Universal (Fat Mach-O)</li>
  <li><strong>Firmware Containers</strong>: UImage, FIT, TRX</li>
  <li><strong>Disk Images</strong>: DMG</li>
  <li><strong>Text Encodings</strong>: IntelHex, SRec, TiTxt</li>
</ul>

<div class="language-python highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="o">&gt;&gt;&gt;</span> <span class="p">[</span><span class="n">x</span><span class="p">.</span><span class="n">name</span> <span class="k">for</span> <span class="n">x</span> <span class="ow">in</span> <span class="n">Transform</span> <span class="k">if</span> <span class="nf">getattr</span><span class="p">(</span><span class="n">x</span><span class="p">,</span> <span class="sh">"</span><span class="s">supports_detection</span><span class="sh">"</span><span class="p">,</span> <span class="bp">False</span><span class="p">)]</span>
<span class="p">[</span><span class="sh">'</span><span class="s">Gzip</span><span class="sh">'</span><span class="p">,</span> <span class="sh">'</span><span class="s">Zlib</span><span class="sh">'</span><span class="p">,</span> <span class="sh">'</span><span class="s">Bzip2</span><span class="sh">'</span><span class="p">,</span> <span class="sh">'</span><span class="s">LZMA</span><span class="sh">'</span><span class="p">,</span> <span class="sh">'</span><span class="s">LZ4Frame</span><span class="sh">'</span><span class="p">,</span> <span class="sh">'</span><span class="s">Zstd</span><span class="sh">'</span><span class="p">,</span> <span class="sh">'</span><span class="s">XZ</span><span class="sh">'</span><span class="p">,</span> <span class="sh">'</span><span class="s">Zip</span><span class="sh">'</span><span class="p">,</span> <span class="sh">'</span><span class="s">CaRT</span><span class="sh">'</span><span class="p">,</span> <span class="sh">'</span><span class="s">Tar</span><span class="sh">'</span><span class="p">,</span> <span class="sh">'</span><span class="s">AR</span><span class="sh">'</span><span class="p">,</span> <span class="sh">'</span><span class="s">CPIO</span><span class="sh">'</span><span class="p">,</span> <span class="sh">'</span><span class="s">DMG</span><span class="sh">'</span><span class="p">,</span> <span class="sh">'</span><span class="s">UImage</span><span class="sh">'</span><span class="p">,</span> <span class="sh">'</span><span class="s">FIT</span><span class="sh">'</span><span class="p">,</span> <span class="sh">'</span><span class="s">TRX</span><span class="sh">'</span><span class="p">,</span> <span class="sh">'</span><span class="s">IntelHex</span><span class="sh">'</span><span class="p">,</span> <span class="sh">'</span><span class="s">SRec</span><span class="sh">'</span><span class="p">,</span> <span class="sh">'</span><span class="s">TiTxt</span><span class="sh">'</span><span class="p">,</span> <span class="sh">'</span><span class="s">IMG4</span><span class="sh">'</span><span class="p">,</span> <span class="sh">'</span><span class="s">LZFSE</span><span class="sh">'</span><span class="p">,</span> <span class="sh">'</span><span class="s">Universal</span><span class="sh">'</span><span class="p">]</span>
</code></pre></div></div>

<h3 id="other-transforms">Other Transforms</h3>

<p>The transforms listed above support <strong>automatic detection</strong>, meaning Binary Ninja can recognize the format and incorporate it into the container resolution tree during file loading.</p>

<p>Binary Ninja also provides many additional transforms that are <strong>not detection-enabled</strong>. These transforms can still be applied manually but are not automatically considered during container discovery.</p>

<p>Common examples include:</p>

<ul>
  <li><strong>Raw compression primitives</strong> (e.g., <code class="language-plaintext highlighter-rouge">Deflate</code>, <code class="language-plaintext highlighter-rouge">LZ4Block</code>, <code class="language-plaintext highlighter-rouge">LZF</code>)</li>
  <li><strong>Encodings</strong> (<code class="language-plaintext highlighter-rouge">Base64</code>, <code class="language-plaintext highlighter-rouge">HexDump</code>, <code class="language-plaintext highlighter-rouge">RawHex</code>)</li>
  <li><strong>Text / language representations</strong> (<code class="language-plaintext highlighter-rouge">CArray</code>, <code class="language-plaintext highlighter-rouge">RustArray</code>, <code class="language-plaintext highlighter-rouge">IntList</code>)</li>
  <li><strong>Cryptographic transforms</strong> (<code class="language-plaintext highlighter-rouge">AES</code>, <code class="language-plaintext highlighter-rouge">DES</code>, <code class="language-plaintext highlighter-rouge">RC4</code>, etc.)</li>
  <li><strong>Simple reversible transforms</strong> (<code class="language-plaintext highlighter-rouge">XOR</code>, <code class="language-plaintext highlighter-rouge">ROL</code>, arithmetic transforms)</li>
</ul>

<p>These transforms typically require parameters, lack reliable file signatures, or would otherwise produce too many false positives if attempted automatically.</p>

<p>They remain accessible through the Transform system and can be applied programmatically:</p>

<div class="language-python highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="n">Transform</span><span class="p">[</span><span class="sh">"</span><span class="s">Base64</span><span class="sh">"</span><span class="p">].</span><span class="nf">decode</span><span class="p">(</span><span class="n">data</span><span class="p">)</span>
<span class="n">Transform</span><span class="p">[</span><span class="sh">"</span><span class="s">Deflate</span><span class="sh">"</span><span class="p">].</span><span class="nf">decode</span><span class="p">(</span><span class="n">data</span><span class="p">)</span>
<span class="n">Transform</span><span class="p">[</span><span class="sh">"</span><span class="s">XOR</span><span class="sh">"</span><span class="p">].</span><span class="nf">decode</span><span class="p">(</span><span class="n">data</span><span class="p">,</span> <span class="p">{</span><span class="sh">"</span><span class="s">key</span><span class="sh">"</span><span class="p">:</span> <span class="sa">b</span><span class="sh">"</span><span class="se">\x42</span><span class="sh">"</span><span class="p">})</span>
</code></pre></div></div>

<p>This design keeps automatic container discovery reliable while still exposing the full transform toolkit for manual analysis workflows.</p>

<h2 id="invocation-model">Invocation Model</h2>

<p>Container transforms participate directly in the standard file loading pipeline, both in the UI and through the <a href="https://api.binary.ninja/#binaryninja.load"><code class="language-plaintext highlighter-rouge">load()</code></a> API. When a file is opened, Binary Ninja evaluates whether the input represents a container and recursively resolves any nested transforms.</p>

<p>The process consists of four stages:</p>

<ol>
  <li><strong>Detection</strong> identifies container formats applicable to the input.</li>
  <li><strong>Transform Resolution</strong> applies matching transforms and recursively evaluates their outputs.</li>
  <li><strong>Context Tree Construction</strong> builds a transformation context tree representing all discovered extraction paths.</li>
  <li><strong>Context Selection</strong> chooses a final derived artifact for analysis.</li>
</ol>

<p>This model allows Binary Ninja to transparently handle arbitrarily nested formats such as compressed archives, firmware containers, or multi-architecture binaries while preserving the full provenance of each transformation step.</p>

<h3 id="automatic-vs-prompted-resolution">Automatic vs Prompted Resolution</h3>

<p>Container resolution may complete automatically or require user input depending on the available choices and required parameters.</p>

<ul>
  <li>
    <p><strong>Automatic resolution</strong> occurs when there is exactly one valid extraction path and no additional parameters (such as passwords) are required. In this case, Binary Ninja opens the derived artifact directly.</p>
  </li>
  <li>
    <p><strong>Prompted resolution</strong> occurs when multiple candidate artifacts exist or when parameters must be provided. The Container Browser presents the available options and allows the user to select the desired artifact or provide required inputs.</p>
  </li>
</ul>

<p>Both resolution modes operate on the same underlying context tree.</p>

<p>The Container Browser also remembers previous selections to streamline repeated workflows. Preferences are cached both <strong>per container type</strong> and <strong>per specific file</strong>, allowing Binary Ninja to automatically default to the previously chosen entry when reopening similar containers or the same file again.</p>

<h2 id="configuration">Configuration</h2>

<p>Container behavior can be adjusted through several settings that control how container detection and resolution occur.</p>

<!-- TODO: When dev goes to stable, make sure to update these with links to the actual live settings docs -->

<ul>
  <li>
    <p><code class="language-plaintext highlighter-rouge">files.container.mode</code>
Controls how container layers are discovered during file loading.</p>

    <ul>
      <li><strong>Disabled</strong>: open the input file without applying container transforms.</li>
      <li><strong>Full</strong> (DEFAULT): discover all possible extraction paths before prompting for selection.</li>
      <li><strong>Interactive</strong>: resolve container layers step-by-step, prompting the user at each stage.</li>
    </ul>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">files.container.autoOpen</code>
Determines whether a single unambiguous extraction path opens automatically or still requires confirmation. Defaults
to <code class="language-plaintext highlighter-rouge">True</code>.</p>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">files.container.defaultPasswords</code>
Provides a list of passwords to attempt automatically when opening password-protected containers. Passwords are tried in order before prompting the user. The default setting is: <code class="language-plaintext highlighter-rouge">["infected","password","123456","admin","test","secret","flare","hackthebox","crackmes.de","crackmes.one"]</code></p>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">files.container.excludedTransforms</code>
Specifies container transforms that should be ignored during automatic detection. Files requiring those transforms will fall back to the standard BinaryView loading path. This can also be overridden per session through load options. Defaults to an empty list.</p>
  </li>
</ul>

<p>These settings modify workflow behavior without changing the underlying container resolution model. For example, malware analysts may prefer fully automatic unwrapping with a predefined password list, while users exploring unfamiliar firmware images may prefer step-by-step resolution at each container layer.</p>

<p>For complete settings documentation, see the <a href="https://docs.binary.ninja/guide/settings.html#files.container.mode">Container Settings Reference</a>.</p>

<h2 id="the-transform-api">The Transform API</h2>

<p>First, let’s check out an example using the structure we showed above, then we’ll talk about the components that make it
up:</p>

<div class="language-python highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="kn">from</span> <span class="n">binaryninja</span> <span class="kn">import</span> <span class="n">TransformSession</span><span class="p">,</span> <span class="n">load</span>

<span class="c1"># Stages 1-3: Detection, transform resolution, and context tree construction
</span><span class="n">session</span> <span class="o">=</span> <span class="nc">TransformSession</span><span class="p">(</span><span class="sh">"</span><span class="s">archive.tar.gz</span><span class="sh">"</span><span class="p">)</span>
<span class="n">session</span><span class="p">.</span><span class="nf">process</span><span class="p">()</span>

<span class="c1"># Walk the resolved context tree
</span><span class="k">def</span> <span class="nf">walk</span><span class="p">(</span><span class="n">ctx</span><span class="p">,</span> <span class="n">depth</span><span class="o">=</span><span class="mi">0</span><span class="p">):</span>
    <span class="n">label</span> <span class="o">=</span> <span class="n">ctx</span><span class="p">.</span><span class="n">transform_name</span> <span class="ow">or</span> <span class="n">ctx</span><span class="p">.</span><span class="n">filename</span> <span class="ow">or</span> <span class="sh">"</span><span class="s">root</span><span class="sh">"</span>
    <span class="nf">print</span><span class="p">(</span><span class="sa">f</span><span class="sh">"</span><span class="si">{</span><span class="sh">'</span><span class="s">  </span><span class="sh">'</span> <span class="o">*</span> <span class="n">depth</span><span class="si">}{</span><span class="n">label</span><span class="si">}</span><span class="s">  (</span><span class="si">{</span><span class="n">ctx</span><span class="p">.</span><span class="n">child_count</span><span class="si">}</span><span class="s"> children)</span><span class="sh">"</span><span class="p">)</span>
    <span class="k">for</span> <span class="n">child</span> <span class="ow">in</span> <span class="n">ctx</span><span class="p">.</span><span class="n">children</span><span class="p">:</span>
        <span class="nf">walk</span><span class="p">(</span><span class="n">child</span><span class="p">,</span> <span class="n">depth</span> <span class="o">+</span> <span class="mi">1</span><span class="p">)</span>

<span class="nf">walk</span><span class="p">(</span><span class="n">session</span><span class="p">.</span><span class="n">root_context</span><span class="p">)</span>
<span class="c1"># Gzip  (1 children)
#   Tar  (3 children)
#     README.md  (0 children)
#     config.json  (0 children)
#     IMG4  (1 children)
#       LZFSE  (1 children)
#         extracted  (0 children)
</span>
<span class="c1"># Stage 4: Find the deepest leaf and load it
</span><span class="k">def</span> <span class="nf">find_leaf</span><span class="p">(</span><span class="n">ctx</span><span class="p">):</span>
    <span class="k">if</span> <span class="n">ctx</span><span class="p">.</span><span class="n">is_leaf</span><span class="p">:</span>
        <span class="k">return</span> <span class="n">ctx</span>
    <span class="k">return</span> <span class="nf">find_leaf</span><span class="p">(</span><span class="n">ctx</span><span class="p">.</span><span class="n">children</span><span class="p">[</span><span class="o">-</span><span class="mi">1</span><span class="p">])</span>

<span class="n">leaf</span> <span class="o">=</span> <span class="nf">find_leaf</span><span class="p">(</span><span class="n">session</span><span class="p">.</span><span class="n">root_context</span><span class="p">)</span>
<span class="n">session</span><span class="p">.</span><span class="nf">set_selected_contexts</span><span class="p">(</span><span class="n">leaf</span><span class="p">)</span>

<span class="k">with</span> <span class="nf">load</span><span class="p">(</span><span class="n">leaf</span><span class="p">.</span><span class="nb">input</span><span class="p">)</span> <span class="k">as</span> <span class="n">bv</span><span class="p">:</span>
    <span class="nf">print</span><span class="p">(</span><span class="n">bv</span><span class="p">.</span><span class="nb">file</span><span class="p">.</span><span class="n">virtual_path</span><span class="p">)</span>
    <span class="c1"># Gzip(.../archive.tar.gz)::Tar()::IMG4(firmware.img4)::LZFSE(krnl...)::extracted
</span>    <span class="nf">print</span><span class="p">(</span><span class="n">bv</span><span class="p">.</span><span class="n">view_type</span><span class="p">)</span>
    <span class="c1"># Mach-O
</span></code></pre></div></div>

<p>The system is built on three core types:</p>

<ul>
  <li><a href="https://api.binary.ninja/binaryninja.transform-module.html#binaryninja.transform.Transform"><code class="language-plaintext highlighter-rouge">Transform</code></a>: capability</li>
  <li><a href="https://api.binary.ninja/binaryninja.transform-module.html#binaryninja.transform.TransformContext"><code class="language-plaintext highlighter-rouge">TransformContext</code></a>: representation</li>
  <li><a href="https://api.binary.ninja/binaryninja.transform-module.html#binaryninja.transform.TransformSession"><code class="language-plaintext highlighter-rouge">TransformSession</code></a>: orchestration</li>
</ul>

<h3 id="transform-capability">Transform: Capability</h3>

<p>A <code class="language-plaintext highlighter-rouge">Transform</code> defines what can decode what. Key properties:</p>

<ul>
  <li><a href="https://api.binary.ninja/binaryninja.transform-module.html#binaryninja.transform.Transform.supports_detection"><code class="language-plaintext highlighter-rouge">supports_detection</code></a>: can the transform auto-select for a given input?</li>
  <li><code class="language-plaintext highlighter-rouge">supports_context</code>: can it operate in context-aware mode for multi-output extraction?</li>
  <li><a href="https://api.binary.ninja/binaryninja.transform-module.html#binaryninja.transform.Transform.parameters"><code class="language-plaintext highlighter-rouge">parameters</code></a>: additional inputs required (encryption keys, passwords, etc.)</li>
</ul>

<div class="language-python highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="c1"># Enumerate all transforms
</span><span class="nf">list</span><span class="p">(</span><span class="n">Transform</span><span class="p">)</span>

<span class="c1"># Look up a transform by name
</span><span class="n">zlib</span> <span class="o">=</span> <span class="n">Transform</span><span class="p">[</span><span class="sh">"</span><span class="s">Zlib</span><span class="sh">"</span><span class="p">]</span>
</code></pre></div></div>

<p>Simple transforms operate directly on bytes:</p>
<div class="language-python highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="n">sha512</span> <span class="o">=</span> <span class="n">Transform</span><span class="p">[</span><span class="sh">"</span><span class="s">SHA512</span><span class="sh">"</span><span class="p">]</span>
<span class="n">rawhex</span> <span class="o">=</span> <span class="n">Transform</span><span class="p">[</span><span class="sh">"</span><span class="s">RawHex</span><span class="sh">"</span><span class="p">]</span>
<span class="n">rawhex</span><span class="p">.</span><span class="nf">encode</span><span class="p">(</span><span class="n">sha512</span><span class="p">.</span><span class="nf">encode</span><span class="p">(</span><span class="sh">"</span><span class="s">test string</span><span class="sh">"</span><span class="p">))</span>
</code></pre></div></div>

<p>Some transforms require parameters:</p>
<div class="language-python highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="n">xor</span> <span class="o">=</span> <span class="n">Transform</span><span class="p">[</span><span class="sh">"</span><span class="s">XOR</span><span class="sh">"</span><span class="p">]</span>
<span class="n">xor</span><span class="p">.</span><span class="nf">encode</span><span class="p">(</span><span class="sa">b</span><span class="sh">"</span><span class="s">Original Data</span><span class="sh">"</span><span class="p">,</span> <span class="p">{</span><span class="sh">"</span><span class="s">key</span><span class="sh">"</span><span class="p">:</span> <span class="sa">b</span><span class="sh">"</span><span class="s">XORKEY</span><span class="sh">"</span><span class="p">})</span>
</code></pre></div></div>

<p>For container formats, the important entry point is <a href="https://api.binary.ninja/binaryninja.transform-module.html#binaryninja.transform.Transform.decode_with_context"><code class="language-plaintext highlighter-rouge">decode_with_context</code></a>, which allows a transform to enumerate files, request user selection, and produce extracted child contexts.</p>

<h3 id="transformcontext-representation">TransformContext: Representation</h3>

<p>A <code class="language-plaintext highlighter-rouge">TransformContext</code> is a node in the extraction tree. It captures:</p>

<ul>
  <li>An input <a href="https://api.binary.ninja/binaryninja.binaryview-module.html#binaryninja.binaryview.BinaryView"><code class="language-plaintext highlighter-rouge">BinaryView</code></a> that represents the bytes at this stage (<a href="https://api.binary.ninja/binaryninja.transform-module.html#binaryninja.transform.TransformContext.input"><code class="language-plaintext highlighter-rouge">context.input</code></a>)</li>
  <li>The name of the transform that produced the data (<a href="https://api.binary.ninja/binaryninja.transform-module.html#binaryninja.transform.TransformContext.transform_name"><code class="language-plaintext highlighter-rouge">context.transform_name</code></a>), which can also be set manually via <a href="https://api.binary.ninja/binaryninja.transform-module.html#binaryninja.transform.TransformContext.set_transform_name"><code class="language-plaintext highlighter-rouge">set_transform_name()</code></a> to specify a transform for non-auto-detected formats</li>
  <li>Transform parameters such as passwords or keys</li>
  <li>Metadata associated with the transformation (<a href="https://api.binary.ninja/binaryninja.transform-module.html#binaryninja.transform.TransformContext.metadata_obj"><code class="language-plaintext highlighter-rouge">context.metadata_obj</code></a>)</li>
  <li>Extraction and transform status, including structured result codes and human-readable messages</li>
  <li>Parent and child relationships that define the container hierarchy</li>
</ul>

<p>Together these fields preserve the provenance of derived artifacts and make the container hierarchy explicit.</p>

<h4 id="execution-model">Execution Model</h4>

<p>Container transforms operate in two phases:</p>

<ol>
  <li><strong>Discovery</strong>: the transform enumerates available artifacts, populates <a href="https://api.binary.ninja/binaryninja.transform-module.html#binaryninja.transform.TransformContext.available_files"><code class="language-plaintext highlighter-rouge">available_files</code></a>, and returns <code class="language-plaintext highlighter-rouge">False</code> to request user selection.</li>
  <li><strong>Extraction</strong>: the transform processes <a href="https://api.binary.ninja/binaryninja.transform-module.html#binaryninja.transform.TransformContext.requested_files"><code class="language-plaintext highlighter-rouge">requested_files</code></a>, creates child contexts for each extracted artifact, and returns <code class="language-plaintext highlighter-rouge">True</code> when extraction is complete.</li>
</ol>

<h4 id="context-metadata">Context Metadata</h4>

<p>Each <code class="language-plaintext highlighter-rouge">TransformContext</code> can also carry format-specific metadata through its <a href="https://api.binary.ninja/binaryninja.transform-module.html#binaryninja.transform.TransformContext.metadata_obj"><code class="language-plaintext highlighter-rouge">metadata_obj</code></a> property. This allows transforms to preserve structured information about the extraction process beyond the raw bytes.</p>

<p>Examples include archive attributes, compression details, encryption parameters, timestamps, or other format-specific information that may be useful to downstream transforms or analysis plugins.</p>

<p>While most current container transforms focus primarily on producing extracted artifacts, the metadata mechanism provides an extensibility point for richer communication between transformation stages when needed.</p>

<h3 id="transformsession-orchestration">TransformSession: Orchestration</h3>

<p><code class="language-plaintext highlighter-rouge">TransformSession</code> drives the extraction workflow over the <code class="language-plaintext highlighter-rouge">TransformContext</code> tree using the available <code class="language-plaintext highlighter-rouge">Transform</code>s.</p>

<p>It coordinates container detection, transform execution, and context selection as nested containers are processed. The session advances extraction automatically when possible and pauses when user input or artifact selection is required.</p>

<p>A session is responsible for:</p>

<ul>
  <li>Detecting and applying transforms for each context</li>
  <li>Traversing nested containers and multi-stage formats</li>
  <li>Constructing and maintaining the context tree</li>
  <li>Managing user selection and transform parameters</li>
  <li>Selecting one or more final contexts for analysis</li>
</ul>

<p>In effect, <code class="language-plaintext highlighter-rouge">TransformSession</code> acts as the policy layer of the container system, controlling how extraction progresses and which derived artifacts ultimately become inputs to analysis.</p>

<p>The session API is intentionally small and focused. The most important operations are:</p>

<ul>
  <li><a href="https://api.binary.ninja/binaryninja.transform-module.html#binaryninja.transform.TransformSession.current_view"><code class="language-plaintext highlighter-rouge">current_view</code></a>, the current <code class="language-plaintext highlighter-rouge">BinaryView</code> for this session</li>
  <li><a href="https://api.binary.ninja/binaryninja.transform-module.html#binaryninja.transform.TransformSession.current_context"><code class="language-plaintext highlighter-rouge">current_context</code></a>, the current <code class="language-plaintext highlighter-rouge">TransformContext</code> being processed</li>
  <li><a href="https://api.binary.ninja/binaryninja.transform-module.html#binaryninja.transform.TransformSession.process"><code class="language-plaintext highlighter-rouge">process()</code></a>, which advances the extraction workflow and returns <code class="language-plaintext highlighter-rouge">True</code> when processing is complete</li>
  <li><a href="https://api.binary.ninja/binaryninja.transform-module.html#binaryninja.transform.TransformSession.process_from"><code class="language-plaintext highlighter-rouge">process_from(context)</code></a>, which resumes processing from a specific context after input or selection has been provided</li>
  <li><a href="https://api.binary.ninja/binaryninja.transform-module.html#binaryninja.transform.TransformSession.set_selected_contexts"><code class="language-plaintext highlighter-rouge">set_selected_contexts(...)</code></a>, which marks one or more contexts as the intended outputs</li>
</ul>

<h3 id="filename-resolution">Filename Resolution</h3>

<p>Container extraction introduces multiple naming layers that serve different roles:</p>

<table>
  <thead>
    <tr>
      <th>Property</th>
      <th>Role</th>
      <th>Description</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td><a href="https://api.binary.ninja/binaryninja.filemetadata-module.html#binaryninja.filemetadata.FileMetadata.filename"><code class="language-plaintext highlighter-rouge">filename</code></a></td>
      <td><strong>Storage</strong></td>
      <td>Physical path on disk (for example the <code class="language-plaintext highlighter-rouge">.bndb</code> path when working with a saved database)</td>
    </tr>
    <tr>
      <td><a href="https://api.binary.ninja/binaryninja.filemetadata-module.html#binaryninja.filemetadata.FileMetadata.original_filename"><code class="language-plaintext highlighter-rouge">original_filename</code></a></td>
      <td><strong>Source</strong></td>
      <td>Path of the original binary that produced the current view</td>
    </tr>
    <tr>
      <td><a href="https://api.binary.ninja/binaryninja.filemetadata-module.html#binaryninja.filemetadata.FileMetadata.virtual_path"><code class="language-plaintext highlighter-rouge">virtual_path</code></a></td>
      <td><strong>Provenance</strong></td>
      <td>Provenance chain produced by the container/transform system (defaults to <code class="language-plaintext highlighter-rouge">filename</code> for non-container files)</td>
    </tr>
    <tr>
      <td><a href="https://api.binary.ninja/binaryninja.filemetadata-module.html#binaryninja.filemetadata.FileMetadata.display_name"><code class="language-plaintext highlighter-rouge">display_name</code></a></td>
      <td><strong>Presentation</strong></td>
      <td>Synthesized path used for UI display (tab titles, save dialogs, etc.; project-aware naming is handled in the UI layer)</td>
    </tr>
  </tbody>
</table>

<p>For files opened directly from disk (without container transforms), these values are typically identical. For extracted artifacts, they diverge:</p>

<div class="language-python highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="c1"># ZIP containing file3.bin, nested inside a .tar.xz
</span><span class="n">bv</span><span class="p">.</span><span class="nb">file</span><span class="p">.</span><span class="n">virtual_path</span>    <span class="c1"># → 'XZ(/path/to/archive.tar.xz)::Tar()::file3.bin'
</span><span class="n">bv</span><span class="p">.</span><span class="nb">file</span><span class="p">.</span><span class="n">display_name</span>    <span class="c1"># → '/path/to/archive/file3.bin'
</span>
<span class="c1"># IMG4 firmware component
</span><span class="n">bv</span><span class="p">.</span><span class="nb">file</span><span class="p">.</span><span class="n">virtual_path</span>    <span class="c1"># → 'IMG4(/path/to/firmware.v59)::LZFSE(krnl.1)::extracted'
</span><span class="n">bv</span><span class="p">.</span><span class="nb">file</span><span class="p">.</span><span class="n">display_name</span>    <span class="c1"># → '/path/to/firmware.v59.krnl.1.extracted'
</span></code></pre></div></div>

<p><code class="language-plaintext highlighter-rouge">virtual_path</code> preserves the <strong>provenance chain</strong> describing how the artifact was produced.
<code class="language-plaintext highlighter-rouge">display_name</code> provides a concise label suitable for UI presentation.</p>

<h3 id="example-nested-archive">Example: Nested Archive</h3>

<div class="language-python highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="kn">from</span> <span class="n">binaryninja</span> <span class="kn">import</span> <span class="n">TransformSession</span><span class="p">,</span> <span class="n">load</span>

<span class="c1"># Create a session for the nested archive
</span><span class="n">session</span> <span class="o">=</span> <span class="nc">TransformSession</span><span class="p">(</span><span class="sh">"</span><span class="s">backup.tar.gz</span><span class="sh">"</span><span class="p">)</span>

<span class="c1"># Process the entire extraction chain
</span><span class="k">if</span> <span class="n">session</span><span class="p">.</span><span class="nf">process</span><span class="p">():</span> <span class="c1"># Returns True if extraction completed successfully
</span>    <span class="c1"># Select and load the final extracted file
</span>    <span class="n">session</span><span class="p">.</span><span class="nf">set_selected_contexts</span><span class="p">(</span><span class="n">session</span><span class="p">.</span><span class="n">current_context</span><span class="p">)</span>

    <span class="k">with</span> <span class="nf">load</span><span class="p">(</span><span class="n">session</span><span class="p">.</span><span class="n">current_view</span><span class="p">)</span> <span class="k">as</span> <span class="n">bv</span><span class="p">:</span>
        <span class="nf">print</span><span class="p">(</span><span class="n">bv</span><span class="p">.</span><span class="nb">file</span><span class="p">.</span><span class="n">virtual_path</span><span class="p">)</span>
        <span class="c1"># 'Gzip(/path/to/backup.tar.gz)::Tar()::data.bin::extracted'
</span></code></pre></div></div>

<h3 id="example-manual-transform-selection">Example: Manual Transform Selection</h3>

<p>Some encodings (such as Base64) do not have reliable signatures for automatic detection. Because they are designed to resemble ordinary text, they must often be applied manually.</p>

<div class="language-python highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="kn">from</span> <span class="n">binaryninja</span> <span class="kn">import</span> <span class="n">TransformSession</span><span class="p">,</span> <span class="n">load</span>

<span class="c1"># First, extract the ZIP archive
</span><span class="n">session</span> <span class="o">=</span> <span class="nc">TransformSession</span><span class="p">(</span><span class="sh">"</span><span class="s">encoded_payload.zip</span><span class="sh">"</span><span class="p">)</span>
<span class="n">session</span><span class="p">.</span><span class="nf">process</span><span class="p">()</span>

<span class="c1"># The extracted file contains Base64-encoded data
</span><span class="n">extracted_ctx</span> <span class="o">=</span> <span class="n">session</span><span class="p">.</span><span class="n">current_context</span>

<span class="c1"># Manually specify the Base64 transform
</span><span class="n">extracted_ctx</span><span class="p">.</span><span class="nf">set_transform_name</span><span class="p">(</span><span class="sh">"</span><span class="s">Base64</span><span class="sh">"</span><span class="p">)</span>

<span class="c1"># Process the transform
</span><span class="k">if</span> <span class="n">session</span><span class="p">.</span><span class="nf">process_from</span><span class="p">(</span><span class="n">extracted_ctx</span><span class="p">):</span> <span class="c1"># Returns True when decoding succeeds
</span>    <span class="c1"># Successfully decoded the Base64 data
</span>    <span class="n">session</span><span class="p">.</span><span class="nf">set_selected_contexts</span><span class="p">(</span><span class="n">session</span><span class="p">.</span><span class="n">current_context</span><span class="p">)</span>

    <span class="k">with</span> <span class="nf">load</span><span class="p">(</span><span class="n">session</span><span class="p">.</span><span class="n">current_view</span><span class="p">)</span> <span class="k">as</span> <span class="n">bv</span><span class="p">:</span>
        <span class="nf">print</span><span class="p">(</span><span class="sa">f</span><span class="sh">"</span><span class="s">Transform chain: </span><span class="si">{</span><span class="n">bv</span><span class="p">.</span><span class="nb">file</span><span class="p">.</span><span class="n">virtual_path</span><span class="si">}</span><span class="sh">"</span><span class="p">)</span>
        <span class="c1"># Example: 'Zip(/path/to/encoded_payload.zip)::Base64(payload.txt)::extracted'
</span></code></pre></div></div>

<p>This approach is useful when working with obfuscated malware, custom encodings, or formats that lack reliable signatures for automatic detection.</p>

<h2 id="a-reference-implementation-zippython">A Reference Implementation: ZipPython</h2>

<p>Binary Ninja includes a complete Python container transform implementation in the public repository: <a href="https://github.com/Vector35/binaryninja-api/blob/dev/python/transform.py#L1102"><code class="language-plaintext highlighter-rouge">ZipPython</code></a>.</p>

<p>It demonstrates:</p>

<ul>
  <li>Signature-based detection via <a href="https://api.binary.ninja/binaryninja.transform-module.html#binaryninja.transform.Transform.can_decode"><code class="language-plaintext highlighter-rouge">can_decode</code></a></li>
  <li>Context-aware decoding using <a href="https://api.binary.ninja/binaryninja.transform-module.html#binaryninja.transform.Transform.decode_with_context"><code class="language-plaintext highlighter-rouge">decode_with_context</code></a></li>
  <li>The two-phase discovery and extraction model</li>
  <li>Multi-file handling and password support</li>
  <li>Creation of child <a href="https://api.binary.ninja/binaryninja.transform-module.html#binaryninja.transform.TransformContext"><code class="language-plaintext highlighter-rouge">TransformContext</code></a> objects</li>
</ul>

<p>If you’re implementing a custom container transform, <code class="language-plaintext highlighter-rouge">ZipPython</code> is the best starting point.</p>

<h2 id="future-directions">Future Directions</h2>

<p>We’re continuing to expand container format support based on user feedback. We’re also exploring ways to improve the Container Browser UI with better visualization of transform chains and metadata inspection.</p>

<p><img src="/blog/images/container/browser-container.png" alt="Container Browser" class="image max-height-500" /></p>

<h2 id="conclusion">Conclusion</h2>

<p>Container Transforms eliminate the tedious manual extraction workflows that previously required multiple tools and steps. Whether you’re analyzing firmware, triaging malware, or exploring disk images, Binary Ninja automatically handles detection, extraction, password management, and multi-layer nesting.</p>

<p>Instead of flattening extracted bytes into memory, the system models container processing as a structured transformation pipeline that preserves provenance and context throughout the analysis process.</p>

<p>The Transform API provides both high-level convenience through <a href="https://api.binary.ninja/#binaryninja.load"><code class="language-plaintext highlighter-rouge">load()</code></a> and fine-grained control through <a href="https://api.binary.ninja/binaryninja.transform-module.html#binaryninja.transform.TransformSession"><code class="language-plaintext highlighter-rouge">TransformSession</code></a>, giving you the flexibility to handle everything from simple archives to deeply nested container formats.</p>

<p>We welcome feedback on these features and suggestions for additional container formats or capabilities that would improve your reverse engineering workflow.</p>

<h2 id="api-reference">API Reference</h2>

<p>For complete API documentation, see:</p>

<ul>
  <li><a href="https://api.binary.ninja/binaryninja.transform-module.html#binaryninja.transform.Transform"><code class="language-plaintext highlighter-rouge">Transform</code></a> - Base transform class</li>
  <li><a href="https://api.binary.ninja/binaryninja.transform-module.html#binaryninja.transform.TransformContext"><code class="language-plaintext highlighter-rouge">TransformContext</code></a> - Container extraction context</li>
  <li><a href="https://api.binary.ninja/binaryninja.transform-module.html#binaryninja.transform.TransformSession"><code class="language-plaintext highlighter-rouge">TransformSession</code></a> - Multi-stage extraction workflow</li>
  <li><a href="https://api.binary.ninja/binaryninja.enums-module.html#binaryninja.enums.TransformResult"><code class="language-plaintext highlighter-rouge">TransformResult</code></a> - Extraction result codes</li>
</ul>]]></content><author><name>Brian Potchik</name><email>brian@vector35.com</email></author><category term="reversing" /><category term="announcements" /><summary type="html"><![CDATA[Firmware analysis, malware triage, and embedded systems reverse engineering often require extracting files from nested container formats: TAR archives inside GZIP files, encrypted firmware wrapped in multiple compression layers, or password-protected ZIPs containing “infected” malware. Manually peeling each layer with separate tools gets old fast. Binary Ninja’s Container Transform system automates this workflow, handling detection, extraction, password management, and multi-layer nesting while preserving the structure and provenance of each stage.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://binary.ninja/blog/images/container/container.png" /><media:content medium="image" url="https://binary.ninja/blog/images/container/container.png" xmlns:media="http://search.yahoo.com/mrss/" /></entry></feed>