Researchers in China have found a way to intercept audio from headphones and other analog devices from up to 30 meters away, including through walls, by injecting electromagnetic signals into their circuits. The technique, called InjectEave, was detailed in a paper presented at USENIX Security 2026 by scientists from The Hong Kong University of Science and Technology and The Hong Kong Polytechnic University. The attack overcomes a longstanding obstacle in electromagnetic eavesdropping: the weakness of radio-frequency signals in devices like headphones makes it hard for attackers to distinguish signal from background noise.
The research team tested InjectEave on 11 commercially available devices, including wired and wireless headphones from Sony, Apple, Philips, and HP, a VoIP landline phone, smart fans from OIDIRE and Xiaomi, and smart lamps from JINGZAO and Xiaomi. For most of these products, the demonstrated attack range fell between 1 and 6 meters, though the team separately showed that headphone eavesdropping could reach 30 meters when using an RF power amplifier. The attack works by transmitting a signal in the 0-9 MHz range—specific frequencies weren't disclosed—which modulates the target audio signal so it becomes detectable by nearby equipment. The technique targets non-linear components common in computer systems, such as amplifiers, analog-to-digital converters, power converters, and switching MOSFETs.
"Our new project, InjectEave, shows that RF signals can induce information leakage from everyday headphones, allowing an attacker to recover headphone audio from up to 30 meters away, including through walls," said Yan Long, assistant professor at HKUST in Guangzhou. The researchers verified the vulnerability across multiple commercial devices from Sony, HP, Philips, and others. The team writes in their paper that "injection-induced side-channel attacks could eavesdrop on the majority of these devices from over 2m away and through walls," adding that their tests indicate these scenarios are realistic in real-world conditions. The attack requires commodity RF equipment: a software-defined radio, antennas for injection and reception, a spectrum analyzer, a laptop for controlling the SDR, and optionally an RF power amplifier to extend range.
The researchers documented practical attack scenarios including listening through hotel room walls and concealing attack hardware in nearby suitcases or office furniture. InjectEave differs from passive electromagnetic eavesdropping by actively manipulating signals rather than simply capturing them, effectively amplifying what would otherwise be too faint to detect. The interplay between the injected signals, the hardware's non-linear components, and the target audio essentially modulates the signal so it leaks and becomes detectable. The report notes that any device with parts handling signal stepping, like power converters, may be vulnerable since non-linear components are widespread in computer systems.
The researchers conclude that InjectEave can't be stopped by digital defenses like encryption, masking, or randomization because the leakage originates from the analog path rather than digital processing. Hardware-aware protections such as twisted-pair wiring, shielding, and filtering can reduce the energy that the injected carrier couples into the device, lowering exposure. These countermeasures raise the difficulty level for attackers but don't guarantee complete protection. The broad applicability of this attack method across everyday consumer devices suggests security teams may need to reconsider which hardware components require hardening, particularly in environments where confidential conversations occur. Physical proximity requirements mean InjectEave won't replace remote digital intrusions, but organizations accustomed to trusting analog components as immune to wireless threats may find their threat models need adjustment.

