Researchers at the Hong Kong University of Science and Technology and the Hong Kong Polytechnic University have demonstrated InjectEave, a technique that can make headphones, a desk phone and some smart-home devices radiate signals that reveal what they are doing.
Presented at USENIX Security 2026 in Baltimore, the research has been reported as showing that an attacker can recover intelligible headphone audio from up to 30 meters away, including through walls. The researchers said the setup could eavesdrop on most tested devices from over 2 meters away, but specialized equipment is conspicuous and speech is harder to recover than test tones.
InjectEave transmits a carrier signal at the target. Nonlinear components then mix audio onto that carrier, which the device's traces and cables radiate to a receiver. Because the leak occurs in the analog path after audio decoding, encryption and other digital defenses cannot stop it. The proof of concept used a USRP B210 software-defined radio, two antennas, a Siglent spectrum analyzer and a laptop. Reaching the full range required continuous transmission and a high-powered 10 W transmitter.
The technique can also affect wired headphones, whose sound cards were identified as the main source of short-range microphone leaks. The attacker must know the target model and profile a matching unit; the researchers transferred one profile across 3 identical UGreen headsets. They said they reported the findings to manufacturers but, without responses, withheld frequency details and injection controls. The idea builds on earlier work and recalls “The Thing,” a remotely powered Soviet listening device presented to the US ambassador in Moscow in 1945.
Comments
0No comments yet. Be the first to comment.