The big picture: Researchers in Hong Kong have developed a technique that uses injected radio signals to extract audio and other information from headphones, phones and smart-home devices. Called InjectEave, the method targets analog components that can leak signals too weak to capture through conventional electromagnetic eavesdropping. In testing, the researchers recovered understandable headphone audio from up to 30 meters away, including through walls.
The research comes from the Hong Kong University of Science and Technology in Guangzhou and the Hong Kong Polytechnic University. The team presented its paper, "Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware Nonlinearity," at USENIX Security 2026.
Traditional electromagnetic side-channel attacks rely on passively collecting radiation emitted by electronics. That's often difficult with audio, since low-frequency signals produce weak emissions that get lost easily in background noise.
InjectEave takes a different route. An attacker transmits an electromagnetic signal toward a device at a frequency between 0 MHz and 9 MHz. The researchers did not disclose the precise settings needed for the attack.
The injected signal interacts with nonlinear parts inside the device, including amplifiers, analog-to-digital converters, power converters and switching MOSFETs. Those components can mix the injected RF signal with audio or other low-frequency activity. The device then emits a modified signal that nearby radio equipment can pick up and analyze.
The researchers used a USRP B210 software-defined radio, antennas, a Siglent SSA3075X Plus spectrum analyzer and a laptop. They also used an RF power amplifier in some tests to increase the range.
The team tested 11 commercial products. They included Sony ZX110AP wired headphones, Apple earbuds, UGreen MAX2 headphones, Philips TAH2020 headphones, HP H231R headphones and a Flyingvoice P23GW VoIP phone. The researchers also tested smart fans from Oidire and Xiaomi, as well as lamps from Jingzao and Xiaomi.
According to the paper, most tests worked at distances greater than two meters, including through walls. Device-specific ranges generally ran from one to six meters. With an RF amplifier, the researchers recovered intelligible headphone audio from up to 30 meters.
"Our new project, InjectEave, shows that RF signals can induce information leakage from everyday headphones, allowing an attacker to recover headphone audio from up to 30 meters away, including through walls," Yan Long, an assistant professor at HKUST in Guangzhou, said in an email to The Register.
Long said the researchers confirmed the issue in devices made by Sony, HP and Philips, among others.
... continue reading