Researchers have developed a novel electromagnetic side-channel attack, dubbed InjectEave, that can extract audio signals from headphones, landline phones, and smart devices by actively injecting radio frequency (RF) signals. This technique overcomes the typical difficulty of detecting faint RF leakage from such devices by modulating the target audio signal, making it detectable from a distance.
The InjectEave method involves transmitting an RF signal in the 0-9 MHz range, which interacts with non-linear components within the target device. This interaction effectively modulates the device's internal audio signal, causing it to leak in a way that can be captured by nearby receiving equipment. The researchers confirmed the vulnerability on multiple commercial devices from manufacturers including Sony, HP, and Philips.
Yan Long, an assistant professor at The Hong Kong University of Science and Technology (HKUST) in Guangzhou, stated that InjectEave demonstrates that RF signals can induce information leakage from everyday headphones, allowing an attacker to recover audio from up to 30 meters away, even through walls. The research was conducted by Long and HKUST co-authors Haoran Yan, Ziyu Shao, and Shuhao Zhang, along with Qinhong Jiang of The Hong Kong Polytechnic University. Their findings are detailed in a paper titled "Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware Nonlinearity," which was presented at USENIX Security 2026.
The attack targets common non-linear components found in computer systems, such as amplifiers, analog-to-digital converters, power converters, and switching MOSFETs. These components are ubiquitous in modern electronics, suggesting a broad range of potential vulnerabilities.
To conduct an InjectEave attack, commodity RF equipment is sufficient, including a USRP B210 software-defined radio, antennas for both injection and reception, a Siglent SSA3075X Plus spectrum analyzer, and a laptop for control. An RF power amplifier can optionally be used to extend the attack range.
The researchers tested InjectEave on 11 off-the-shelf devices, demonstrating its effectiveness in various scenarios. These included wired headphones (Sony ZX110AP, 2014; Apple Earbuds, 2016), wireless headphones (UGreen MAX2, 2024; Philips TAH2020, 2025; HP H231R, 2023), a VoIP landline phone (Flyingvoice P23GW, 2023), smart fans (OIDIRE ODI-MF10A, 2023; Xiaomi BPLDS10DM, 2025), and smart lamps (JINGZAO JDO-06, 2024; Xiaomi 1S, 2019).
Tests showed that eavesdropping was possible on most of these devices from over 2 meters away and through walls. For headphones, intelligible audio recovery was achieved at a maximum distance of 30 meters when using an RF amplifier. Without an amplifier, the maximum demonstrated attack range was generally between 1 and 6 meters for the listed devices. The researchers also documented plausible scenarios where attack hardware could be concealed in a suitcase or office furniture.
The researchers emphasized that InjectEave is immune to digital defenses like encryption, masking, and randomization because the leakage originates from the analog signal path. While hardware-aware mitigations such as twisted-pair wiring, shielding, and filtering can reduce the energy coupled into the device by the injected carrier, thereby lowering exposure, they do not guarantee complete immunity.





