How it works
Common electromagnetic side channels are passive. The attacker waits for whatever the device radiates on its own and tries to piece something together from it. Audio, however, is too low in frequency for conductors to radiate it effectively, which is exactly why InjectEave actively transmits a carrier wave into the target. For ethical reasons, the authors did not publish the exact frequencies, so an attacker has to tune them for each model on their own. arXiv ↗ InjectEave ↗Inside is then a component that does not behave linearly, meaning its output is not an exact copy of its input. In wired headphones, this is the amplifier in the sound card of the source, that is, the laptop or phone, and the cable itself serves as an antenna. In wireless ones, it is the amplifier in the Bluetooth module. The audio is mixed onto the supplied carrier wave and radiated into the surroundings. The researchers captured it with a USRP B210 radio and a laboratory spectrum analyzer, that is, not with ordinary consumer equipment. arXiv ↗ RTL-SDR ↗
The consequence is unpleasant. The leak occurs in the analog part of the chain, that is, only after the device has decrypted and decoded the audio. According to the authors, neither encryption, masking nor randomization can help, because a continuous analog signal cannot be mathematically masked without corrupting the audio itself. arXiv ↗ The Register ↗
How far are those thirty meters really
The number from the headlines needs clarification. The usual range for individual devices is one to six meters. The authors reached thirty meters only on two wireless headphones, and only by raising the transmitter power from 18 to 40 decibels with an external amplifier costing roughly 415 dollars. arXiv ↗ TechSpot ↗Obstacles did not stop the attack. The audio was captured even through a thirty-centimeter concrete wall of a hotel room, although only from a distance of more than one meter. The researchers also tried it with a prototype hidden in a suitcase, in a meeting room and in an office. arXiv ↗
What could be eavesdropped on
The team tested eleven configurations. They included wired Sony ZX110AP headphones connected once to a Dell laptop and once to a Mac, wired Apple headphones connected to an iPhone, wireless Ugreen MAX2, Philips TAH2020 and HP H231R models, a Flyingvoice P23GW office internet phone, Oidire and Xiaomi fans, and Jingzao and Xiaomi lamps. arXiv ↗ TechSpot ↗The demonstration on that phone went furthest. The researchers built a closed loop in which the system first eavesdrops on the speaker, then, after capturing agreed-upon keywords, clones their voice with a speech synthesis tool and injects an artificially produced sentence into the phone's audio path. Eavesdropping and injection alternate rather than running at the same time, the work used synthesized texts rather than calls of real people, and the attacker stood fifty centimeters from the phone behind a twenty-centimeter office wall. arXiv ↗
Limits of this picture
The paper went through peer review and was presented at the conference. The authors also published the code, but without the control logic for active injection. We are not aware of any independent replication of the attack by another team so far. According to their own account, the authors informed the manufacturers, but had received no response at the time the paper was written. arXiv ↗ InjectEave ↗Nor is the attack something that could be launched from a desk. It requires radio equipment within range of the target and frequency tuning for the specific model. With microphone inputs, the range drops to roughly thirty centimeters. It is therefore more a scenario for targeted surveillance than a broad threat to the average user.
The proposed defenses are shielding, filtering, differential signaling and a twisted pair instead of an ordinary cable. In the authors' measurement, the twisted pair reduced the signal-to-noise ratio by 10.7 decibels, but according to them it does not guarantee protection, because the leak grows with transmitter power. arXiv ↗
⚠️ Be careful when reading foreign reports about this attack. Several media outlets cited a specific frequency band taken from a table in the paper in which the authors deliberately replaced the actual values with placeholder digits. It has also repeatedly been reported that AirPods were among the tested devices, although the paper lists Apple's wired headphones.
What hotinfo is watching
- One of the manufacturers of the tested devices has commented on the findings
- An independent team has reproduced or challenged the attack
- A defence has appeared that actually stops the leak in the analogue path
Illustration photo: an anechoic chamber for electromagnetic compatibility measurements at the Nemko laboratory in Norway. It is unrelated to the research itself; it shows the type of environment in which such measurements are made. The image is from 2012. Author Grethe Spongsveen, Wikimedia Commons, license CC BY-SA 4.0.







