The big picture: Researchers in Hong Kong have developed a technique that uses injected radio signals to extract audio and other information from headphones, phones and smart-home devices. Called InjectEave, the method targets analog components that can leak signals too weak to capture through conventional electromagnetic eavesdropping. In testing, the researchers recovered understandable headphone audio from up to 30 meters away, including through walls.

The research comes from the Hong Kong University of Science and Technology in Guangzhou and the Hong Kong Polytechnic University. The team presented its paper, "Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware Nonlinearity," at USENIX Security 2026.

Traditional electromagnetic side-channel attacks rely on passively collecting radiation emitted by electronics. That's often difficult with audio, since low-frequency signals produce weak emissions that get lost easily in background noise.

InjectEave takes a different route. An attacker transmits an electromagnetic signal toward a device at a frequency between 0 MHz and 9 MHz. The researchers did not disclose the precise settings needed for the attack.

The injected signal interacts with nonlinear parts inside the device, including amplifiers, analog-to-digital converters, power converters and switching MOSFETs. Those components can mix the injected RF signal with audio or other low-frequency activity. The device then emits a modified signal that nearby radio equipment can pick up and analyze.

The researchers used a USRP B210 software-defined radio, antennas, a Siglent SSA3075X Plus spectrum analyzer and a laptop. They also used an RF power amplifier in some tests to increase the range.

The team tested 11 commercial products. They included Sony ZX110AP wired headphones, Apple earbuds, UGreen MAX2 headphones, Philips TAH2020 headphones, HP H231R headphones and a Flyingvoice P23GW VoIP phone. The researchers also tested smart fans from Oidire and Xiaomi, as well as lamps from Jingzao and Xiaomi.

According to the paper, most tests worked at distances greater than two meters, including through walls. Device-specific ranges generally ran from one to six meters. With an RF amplifier, the researchers recovered intelligible headphone audio from up to 30 meters.

"Our new project, InjectEave, shows that RF signals can induce information leakage from everyday headphones, allowing an attacker to recover headphone audio from up to 30 meters away, including through walls," Yan Long, an assistant professor at HKUST in Guangzhou, said in an email to The Register.

Long said the researchers confirmed the issue in devices made by Sony, HP and Philips, among others.

The team also tested scenarios involving equipment hidden in a suitcase, behind a hotel-room wall or inside office furniture. The experiments suggest the attack could be carried out outside a lab, although it still requires nearby radio equipment and knowledge of how a given device responds to the injected signal.

Headphones and phones are the most obvious targets because they may carry private conversations. But the technique could also reveal activity in a home or office. With smart lamps and fans, the team said it could capture control signals and power-use patterns that may indicate when devices are being used.

The researchers said conventional digital protections would not stop InjectEave because the leakage occurs in the analog hardware path, rather than in encrypted data or software.

"InjectEave is immune to digital defenses such as encryption, masking, and randomization, because the leakage comes from the analog path," the researchers wrote.

They said shielding, filtering and twisted-pair wiring can reduce the amount of RF energy that reaches vulnerable components. Those measures may make the attack harder to carry out, but the researchers said they do not guarantee protection.