Researchers have introduced a groundbreaking electromagnetic attack named InjectEave, allowing adversaries to intercept audio from both wired and wireless headphones up to 30 meters away. This method leverages readily available radio-frequency equipment, enabling eavesdropping even through physical barriers.
Development and Publication
The InjectEave technique was crafted by experts from the Hong Kong University of Science and Technology (Guangzhou) and the Hong Kong Polytechnic University. Their findings were shared in a paper titled “Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware Nonlinearity,” which was accepted at USENIX Security ’26.
This innovative approach diverges from traditional electromagnetic attacks by actively injecting a specific radio-frequency signal into the target device, rather than passively capturing stray emissions.
Mechanism of the InjectEave Attack
InjectEave injects a radio-frequency signal that interacts with nonlinear components in electronics, such as audio amplifiers and ADCs, commonly found in headphones and smart devices. This process causes the secret audio signal to mix with the carrier frequency, effectively allowing the audio to be transmitted over greater distances.
Researchers describe this as an “Injection-Modulation-Emission” model, where the injected signal combines with the device’s internal circuitry, resulting in the re-radiation of the mixed signal. The strength of the leaked signal is proportional to both the audio amplitude and the injection power used.
Testing and Implications
The research team utilized an Ettus USRP B210 software-defined radio, log-periodic antennas, and a spectrum analyzer, testing the attack on various commercial devices. With the addition of a $415 external power amplifier, the eavesdropping range extended to 30 meters, maintaining high audio clarity even through walls.
The attack’s ability to penetrate walls with minimal signal loss poses significant security concerns, particularly in environments like offices and hotels. The team also demonstrated the potential for synthesizing and injecting fake audio into devices, further highlighting the attack’s versatility.
Future Outlook and Security Considerations
Despite existing defenses like cryptographic masking, InjectEave’s targeting of continuous analog signals presents new challenges. The study suggests that a combined hardware-software approach will be necessary to mitigate this vulnerability in headphones and IoT devices.
This research underscores the need for enhanced security measures in device design to protect against emerging electromagnetic threats.
