ZeroHour
The Register · Securitypublished ()ingested Thomas Claburn

Researchers find way to listen in on headphones from afar

lowResearchimportance 48
AI summary · glm-5.3-flash

Researchers unveiled InjectEave, an electromagnetic injection side-channel attack that recovers audio from headphones and landline phones up to 30 meters away through walls.

Researchers from HKUST and The Hong Kong Polytechnic University presented InjectEave at USENIX Security 2026, an active EM side-channel attack that injects 0-9 MHz RF signals into nonlinear components such as amplifiers, ADCs, and power converters to modulate and leak target audio. Tested on 11 off-the-shelf devices including Sony, HP, Philips, Apple, and Xiaomi products, the attack recovered intelligible headphone audio from up to 30 meters with an RF amplifier, generally 1-6 meters otherwise, including through walls. The attack uses commodity gear such as a USRP B210 SDR and a Siglent spectrum analyzer, is immune to digital defenses like encryption, and is only partially mitigated by shielding, twisted-pair wiring, and filtering.

  • InjectEave injects 0-9 MHz RF signals into nonlinear hardware to induce detectable audio leakage
  • Recovered intelligible headphone audio from up to 30 meters away, including through walls
  • Verified on 11 commercial devices from Sony, HP, Philips, Apple, Xiaomi, and others
  • Requires commodity equipment: USRP B210 SDR, antennas, and Siglent SSA3075X Plus spectrum analyzer
  • Immune to encryption and masking; shielding and filtering only reduce exposure
Full article709 words · extracted from theregister.com · click to collapse

REG AD

security

Eve's dropping in on Alice and Bob

READ MORE

No content

Researchers based in China have devised a way to eavesdrop on signals handled by analog components in devices such as headphones, landline handsets, and smart devices by injecting electromagnetic (EM) signals.

The technique, referred to as InjectEave, is not simply listening in on a low-frequency analog signal. It's an EM side-channel attack that overcomes one of the longstanding barriers to exploiting EM leakage: the faintness of RF signals in devices like headphones makes it difficult for adversarial listeners to separate signal from noise.

Many different RF side-channel attacks have been explored, such as reading screen display emissions to reconstruct on-screen text or detecting the RF signals emitted by keys on a keyboard. But these techniques often prove impractical for passive EM capture because of the low signal-to-noise ratio.

REG AD

InjectEave trades passive signal capture for active signal manipulation. By transmitting a signal in the 0-9 MHz range – specifics have been withheld – an attacker can potentially modulate an otherwise difficult-to-detect audio signal so it can be captured by nearby equipment.

REG AD

"Our new project, InjectEave, shows that RF [radio frequency] signals can induce information leakage from everyday headphones, allowing an attacker to recover headphone audio from up to 30 meters away, including through walls," said Yan Long, assistant professor at The Hong Kong University of Science and Technology (HKUST) in Guangzhou, in an email to The Register. "We have verified the new vulnerability on multiple commercial devices including devices from Sony, HP, Philips, etc."

Long and HKUST co-authors Haoran Yan, Ziyu Shao, and Shuhao Zhang, along with Qinhong Jiang of The Hong Kong Polytechnic University, describe their work in a paper [PDF] titled "Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware Nonlinearity," which was presented at USENIX Security 2026.

The attack targets non-linear components found in computer systems, such as amplifiers, analog-to-digital converters, power converters, and switching MOSFETs. The interplay of the injected signals, the hardware, and the target audio signals essentially modulates the target signal so that it leaks and is detectable by the adversary.

Conducting an InjectEave attack requires commodity RF equipment: a USRP B210 software-defined radio; antennas for injection and reception; a Siglent SSA3075X Plus spectrum analyzer; a laptop for controlling the SDR; and optionally an RF power amplifier to increase attack range.

The researchers tested the technique with 11 off-the-shelf devices. One obvious application would be espionage, allowing an attacker to listen in on conversations carried over headphones or a landline phone. It could also be used to infer personal activities in households with smart fans or lamps through the monitoring and analysis of control signals and power consumption.

Tested devices include: Sony ZX110AP (2014, wired headphones); Apple Earbuds (2016, wired earbuds); UGreen MAX2, Philips TAH2020, HP H231R (2024, 2025, 2023 wireless headphones); Flyingvoice P23GW (2023, VoIP landline); OIDIRE ODI-MF10A and Xiaomi BPLDS10DM (2023, 2025 smart fans); and JINGZAO JDO-06 and Xiaomi 1S (2024, 2019 smart lamps).

"Our tests show that injection-induced side-channel attacks could eavesdrop on the majority of these devices from over 2m away and through walls, with a maximum distance of 30m for recovering intelligible headphone audio," the researchers state in their paper, noting that their tests indicate these scenarios are plausible in the wild.

For the devices listed by the researchers, the maximum demonstrated attack range was generally between 1 and 6 meters, although they separately demonstrated headphone eavesdropping at up to 30 meters using an RF amplifier.

REG AD

Even so, the researchers documented various scenarios where eavesdropping could be done through hotel room walls and using attack hardware concealed in a nearby suitcase or within office furniture.

The researchers note that non-linear components are common in computer systems and that any device with parts that handle signal stepping (e.g. power converters) may be vulnerable to InjectEave. 

"InjectEave is immune to digital defenses such as encryption, masking, and randomization, because the leakage comes from the analog path," the researchers conclude. "Hardware-aware mitigations such as twisted-pair wiring, shielding, and filtering can lower the energy that the injected carrier couples into the device, reducing the exposure. These mitigations raise the bar, but they do not guarantee immunity." ®

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.theregister.com/security/2026/09/17/researchers-find-way-to-listen-in-on-headphones-from-afar/5297303