Researchers have unveiled a novel electromagnetic (EM) attack called InjectEave that lets an adversary eavesdrop on audio playing through wired and wireless headphones from as far as 30 meters away, even through walls, using nothing more than commercially available radio-frequency equipment.
The technique, developed by a team from the Hong Kong University of Science and Technology (Guangzhou) and the Hong Kong Polytechnic University, was published as “Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware Nonlinearity,” accepted at USENIX Security ’26.
InjectEave Attack Recovers Headphone Audio From 30 Meters
Unlike traditional EM side-channel attacks, which passively sniff stray electromagnetic emissions leaking from a device, InjectEave actively injects a tuned radio-frequency carrier signal into the target device.
This injected signal interacts with nonlinear hardware components inside everyday electronics, such as audio amplifiers, analog-to-digital converters (ADCs), power converters, and switching MOSFETs, which are ubiquitous in headphones, smart home gadgets, and landline phones.
These components unintentionally “mix” the secret analog signal, like an audio waveform, with the injected carrier, effectively piggybacking the low-frequency secret onto a much higher-frequency EM wave that can travel far beyond what passive eavesdropping would allow.
The researchers describe this as an “Injection-Modulation-Emission” model, where the injected carrier couples into a device’s internal circuitry, mixes with the secret signal through hardware nonlinearity, and then re-radiates from the same wires and cables that acted as unintentional antennas in the first place.
Crucially, the leaked signal’s strength scales almost linearly with both the secret signal’s amplitude and the attacker’s injection power, meaning a more powerful transmitter directly translates into a stronger, more recoverable eavesdropping signal.
Conventional EM side-channel eavesdropping has always been constrained by a fundamental physics problem: secrets like human speech occupy frequencies between 20 Hz and 20 kHz, while efficient EM radiation from a device’s wiring typically requires frequencies in the megahertz-to-gigahertz range.
This mismatch has historically kept passive audio eavesdropping distances limited to under 1.5 meters in prior research such as MagEar and Periscope. InjectEave sidesteps this barrier entirely by actively shaping the leakage instead of just listening for it, allowing attackers to select and tune an optimal injection frequency for each target device.
Using an Ettus USRP B210 software-defined radio, log-periodic antennas, and a spectrum analyzer, the research team tested InjectEave against 11 commercial off-the-shelf devices, including wired headphones from Sony, Dell, and Apple, wireless headphones from UGreen, Philips, and HP, a Flyingvoice VoIP landline, and smart fans and lamps from Xiaomi and other brands.
At a baseline distance of 50 centimeters, the attack achieved near-100% audio recognition rates across almost every audio device tested, with signal-to-noise ratios ranging from about 6 dB for Apple Earbuds to over 23 dB for the UGreen MAX2 wireless headphones.
When the team swapped in an external power amplifier costing roughly $415, boosting injection power from 18 dBm to 40 dBm, the effective eavesdropping range on the UGreen MAX2 and Philips TAH2020 headphones extended to a striking 30 meters, all while remaining able to recover intelligible speech.
The attack also proved resilient against physical barriers: glass and wood caused negligible signal loss of 1 to 2 dB, while even solid concrete walls only reduced signal strength by around 5.8 dB for headphones, enabling reliable through-wall eavesdropping in offices, hotels, and conference rooms.
| Attack Parameter | Passive EM Eavesdropping (Prior Art) | InjectEave Active EM Injection |
| Methodology | Listens for stray EM leakage | Actively injects RF carrier to induce mixing |
| Typical Range | < 1.5 meters | Up to 30 meters with external amplifier |
| Barrier Penetration | Highly degraded by walls | Penetrates solid concrete with minimal loss (~5.8 dB) |
| Required Hardware | Software-defined radio (SDR) and antennas | SDR, antennas, and RF power amplifier (~$415) |
| Vulnerable Components | High-frequency digital buses (HDMI, etc.) | Analog amplifiers, ADCs, and power converters |
| Target Examples | PC monitors, smart speakers | Headphones, landline phones, smart lamps/fans |
As detailed in the technical disclosure published in ArXiv, the study’s teardown analysis found that twisted-pair cabling reduced leakage by up to 20 dB compared to standard parallel wiring, offering hardware manufacturers a practical, if partial, mitigation path going forward.
Perhaps most alarming, the researchers demonstrated a closed-loop “Eavesdrop-Synthesize-Inject” attack against a Flyingvoice landline phone.
In this scenario, the attacker first eavesdrops on one party’s voice to build context, clones that voice using an AI voice-cloning tool called IndexTTS-2 upon detecting trigger keywords like “quote” or “confirmation,” and then injects synthesized, deepfaked audio back into the target’s headset, all in real time.
Testing showed the injected fake audio was nearly indistinguishable from the original speaker’s voice, with only a 0.071 average deviation in a standard speech-intelligibility metric.
To improve audio clarity from the inherently noisy, harmonic-distorted leaked signal, the team built InjectEave’s signal-enhancement module around a diffusion-based speech-denoising model trained on physics-simulated data, boosting recovered audio’s signal-to-noise ratio from 7.0 dB to 16.1 dB and its intelligibility score from 0.58 to 0.72.
The attack isn’t limited to headphones. The same principle exposed power consumption patterns of smart lamps and fans, letting attackers remotely infer a household’s activity patterns, sleep schedules, and appliance usage without any network access.
The researchers also found early evidence that microphone inputs are vulnerable, though currently limited to roughly 30 centimeters due to microphones’ much weaker signal levels.
Existing defenses like cryptographic masking and EM shielding largely fail here, since InjectEave targets continuous analog signals rather than digital logic, and a determined attacker can simply crank up injection power to overcome standard shielding.
The researchers stress that comprehensive, security-aware hardware-software co-design will be needed to close this newly exposed analog attack surface across headphones, IoT devices, and beyond.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
The post New InjectEave Attack Allows Hackers to Recover Audio Playing on Headphones from 30 Meters appeared first on Cyber Security News.
