{
  "id": 8531302,
  "title": "Researchers found a way to eavesdrop on headphones from 30 meters away, and encryption can't stop it",
  "url": "https://urgent.news/2026/09/19/researchers-found-a-way-to-eavesdrop-on-headphones-from-30-meters",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-19T20:09:00.000Z",
  "source": {
    "name": "TechSpot",
    "slug": "techspot",
    "url": "https://www.techspot.com/news/113907-researchers-found-way-eavesdrop-headphones-30-meters-away.html"
  },
  "original_language": "en",
  "account": "Researchers in Hong Kong have devised a method to surreptitiously capture audio from headphones, phones, and smart-home devices using injected radio signals. Known as InjectEave, the technique is designed to target analog components that emit weak signals beyond the reach of conventional electromagnetic eavesdropping. The research, conducted by Hong Kong University of Science and Technology and Hong Kong Polytechnic University, was presented at USENIX Security 2026.\n\nTraditional methods of side-channel attacks passively collect electromagnetic radiation emitted by electronics, often proving challenging with audio signals due to their weak emissions that are easily lost in background noise. InjectEave, however, adopts a distinct approach. An attacker transmits an electromagnetic signal at a frequency between 0 MHz and 9 MHz towards a device. The injected signal then interacts with nonlinear parts inside the device, including amplifiers, analog-to-digital converters, power converters, and switching MOSFETs.\n\nThese components mix the injected RF signal with audio or other low-frequency activities. The device subsequently emits a modified signal that can be picked up by nearby radio equipment for analysis. The researchers utilized a software-defined radio, antennas, a spectrum analyzer, and a laptop for their experiments, and an RF power amplifier in some tests to increase the range. They tested 11 commercial products, including Sony wired headphones, Apple earbuds, UGreen MAX2 headphones, Philips headphones, HP headphones, and a VoIP phone.\n\nThe researchers discovered that most tests were successful at distances exceeding two meters, including through walls. Device-specific ranges typically ranged from one to six meters. With the use of an RF amplifier, the researchers were able to recover intelligible headphone audio from a distance of up to 30 meters. Yan Long, an assistant professor at HKUST, emphasized that InjectEave demonstrates the potential for RF signals to induce information leakage from everyday headphones, enabling attackers to recover audio from up to 30 meters away, even through walls.\n\nThe researchers confirmed the vulnerability in devices from Sony, HP, and Philips, among others. They also tested scenarios involving equipment concealed in a suitcase, behind a hotel-room wall, or integrated into office furniture. These findings suggest that the attack could be executed outside a laboratory setting, though it still necessitates the presence of nearby radio equipment and knowledge of how a particular device responds to the injected signal.\n\nHeadphones and phones are the most apparent targets due to their potential to carry private conversations. However, the technique could also reveal activity within homes or offices. Smart lamps and fans were also tested, allowing the capture of control signals and power-use patterns that may indicate when devices are being used. The researchers concluded that traditional digital protections, such as encryption, masking, and randomization, are ineffective against InjectEave, as the leakage originates from the analog hardware path. They noted that shielding, filtering, and twisted-pair wiring can mitigate the amount of RF energy reaching vulnerable components, but these measures do not guarantee protection.",
  "summary": "The research comes from the Hong Kong University of Science and Technology in Guangzhou and the Hong Kong Polytechnic University. The team presented its paper, \"Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware Nonlinearity,\" at USENIX Security 2026. Read Entire Article",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}