
Security researchers have demonstrated a new electromagnetic attack that can recover audio playing through ordinary wired and wireless headphones, with intelligible speech captured from as far as 30 meters away.
The technique, called InjectEave, can also operate through walls and expose information from smart-home devices and landline phones.
The research was conducted by researchers from the Hong Kong University of Science and Technology (Guangzhou) and Hong Kong Polytechnic University.
InjectEave differs from conventional electromagnetic eavesdropping because it does not simply listen for signals a device naturally emits. Instead, the attacker transmits a carefully selected radio-frequency signal toward the target. Nonlinear electronic components inside the device, including amplifiers, analog-to-digital converters, power converters, and switching transistors, can unintentionally mix internal analog signals with that injected carrier. The resulting radio emissions can then contain information about the original signal.

Arxiv
The researchers tested the approach against 11 commercial devices, including wired headphones connected to Dell, Apple, and Mac systems, wireless headphones from UGreen, Philips, and HP, a Flyingvoice landline phone, Xiaomi and OIDIRE smart fans, and Xiaomi and JINGZAO lamps. These are examples used for the research rather than evidence that every product from those manufacturers is vulnerable.

In baseline experiments, the researchers recovered signals from wireless headphones at distances of up to six meters, depending on the model. More capable receiving equipment extended that range further, while a separate long-range experiment described by the authors recovered intelligible headphone audio from up to 30 meters.
Walls were not necessarily an effective barrier. In hotel-room and meeting-room experiments, the team eavesdropped on a UGreen MAX2 headset from an adjacent room through a 30-centimeter concrete wall. A speech-enhancement system was then used to reduce the noise and distortion introduced by the attack.

Arxiv
InjectEave also exposed less obvious forms of private information. Signals from smart-fan motor controls could reveal operating modes and speeds, potentially indicating occupancy or sleep patterns. Power-related leakage from smart lamps allowed researchers to distinguish brightness levels, which they say could similarly expose household routines.
A landline-phone experiment went a step further. The researchers demonstrated a closed-loop scenario in which electromagnetic techniques could be used both to recover a conversation and to inject manipulated audio back into the phone's voice interface, combining eavesdropping with signal manipulation.

Arxiv
Despite the impressive results, InjectEave has significant practical limitations. The attacker needs RF transmitting and receiving hardware, must identify frequencies that work well against the particular target, and benefits from having access to another unit of the same model for profiling. Range also varies substantially between devices.







Leave a Reply