Skip to content

Security1 publisher2 min readPublished

InjectEave makes headphones leak audio through a wall from 30 meters away

The technique injects a 0-9 MHz signal into non-linear analog parts so audio too faint to read passively becomes capturable by nearby gear. It has been demonstrated on Sony, HP and Philips hardware.

The Watch · Security desk

Illustration accompanying InjectEave makes headphones leak audio through a wall from 30 meters away

What happened

  • Researchers at The Hong Kong University of Science and Technology and The Hong Kong Polytechnic University built InjectEave, which eavesdrops on audio in analog components of headphones and landline phones by injecting electromagnetic signals.
  • The attacker transmits in the 0-9 MHz range to modulate an audio signal that is otherwise undetectable, making it capturable by equipment nearby.
  • In the demonstrations, headphone audio was recovered from up to 30 meters away, including through walls.
  • The team verified the attack on multiple commercial devices from brands including Sony, HP and Philips.
  • The target is non-linear analog parts such as amplifiers and converters, which are common across consumer and office electronics.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Audio in a room becomes reachable without an implant, an account or network access, so the endpoint telemetry an incident team would normally pull has nothing to show.
  • constraint Remediation is a hardware job, shielding and filtering, and the researchers say neither guarantees immunity, so no patch cycle closes this.
  • precedent Any earlier assessment that wrote off a device because its emissions were too weak to read was made under a passive assumption that an injecting attacker no longer has to accept.

An InjectEave attacker needs a transmitter inside range of the target device in the 0-9 MHz band and receiving equipment nearby to pick up the modulated audio [5]. In the researchers' tests that range reached 30 meters and held through walls [6]. A 30-meter radius covers about 2,800 square meters, so the attacker can work from the other side of the wall [11][12].

The injection acts on non-linear analog parts, amplifiers and converters among them [4]. Those sit under the layer where software controls apply, and the researchers report the attack works on analog paths and is immune to digital defenses such as encryption [8]. Nothing has to run on the target [15]. Earlier attempts to read these devices passively were defeated by low signal-to-noise ratios, and The Register describes InjectEave as manipulating the signal actively instead of capturing it passively [3][2].

For most estates this changes nothing this quarter. An attacker has to pick the room, identify the device, and hold a position within tens of meters for as long as the conversation runs. That cost is worth paying against a small number of rooms, and landline handsets are in scope there alongside headsets [1]. The researchers also point at smart-home inference, reading emissions from devices such as smart fans and lamps to work out what is going on in a house, and at espionage [10].

So far there is only a summary. The scworld brief credits The Register as its source [13] and does not list the transmit power, the antenna, the receiving equipment, or the model numbers of the Sony, HP and Philips units that were tested [14]. Whether 30 meters repeats outside a lab depends on those parameters.

What to watch

  • Publication of the full paper with transmit power, antenna and receiver details, which would show whether 30 meters is repeatable outside a lab.
  • Any response from Sony, HP or Philips, and whether a shipping product gets a filtering change.
  • Whether the same injection works on input stages such as microphone preamplifiers, not only on audio output paths.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories