Ordinary electronics can leak the sound passing through them to an attacker several rooms away. Researchers from the Hong Kong University of Science and Technology and the Hong Kong Polytechnic University showed how, in an attack they call InjectEave, presented at the USENIX Security 2026 conference.
The attacker beams a low-frequency radio signal, up to 9 MHz, at the device. Nonlinear parts of the electronics, such as amplifiers and voltage converters, mix that signal with the audio and radiate it back. The attacker then captures and decodes it.
Yan Long, an assistant professor at HKUST in Guangzhou, wrote to The Register that radio signals "can induce information leakage from everyday headphones, allowing an attacker to recover headphone audio from up to 30 meters away, including through walls."
What it works on
The team tested wired headphones from Sony and Apple, including Sony's ZX110AP model from 2014, as well as wireless headphones from UGreen, Philips, and HP. The list also included a Flyingvoice VoIP phone and smart fans and lamps, some of them from Xiaomi.
The typical range is one to six meters, including through a wall. With a signal amplifier, the researchers recovered audio from up to 30 meters.
Off-the-shelf gear
The equipment is commercially available: a USRP B210 software-defined radio, antennas for sending and receiving, a Siglent SSA3075X Plus spectrum analyzer, and a laptop. The Register does not report any vendor responses or patches.
The authors say twisted wires, shielding, and filtering reduce how much signal gets into a device. None of them guarantees full protection.