A newly disclosed electromagnetic attack, dubbed InjectEave, can recover audio played through consumer headphones from as far as 30 meters away.
Unlike conventional EM side-channel attacks that passively collect weak stray emissions, InjectEave actively transmits a tuned radio-frequency signal toward a target device to induce stronger, recoverable leakage.
The technique was developed by researchers from the Hong Kong University of Science and Technology (Guangzhou) and the Hong Kong Polytechnic University.
New InjectEave Attack Lets Attackers Eavesdrop
Their paper, “Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware Nonlinearity,” was accepted at USENIX Security ’26. Traditional EM eavesdropping faces a major physics limitation.
Speech and other audio signals generally occupy frequencies between 20 Hz and 20 kHz, whereas device wiring more efficiently radiates at much higher megahertz-to-gigahertz frequencies.

As a result, previous passive attacks, including MagEar and Periscope, were generally limited to distances below 1.5 meters. InjectEave bypasses that limitation by transmitting an RF carrier that couples into a target’s internal circuitry.
Nonlinear components, including audio amplifiers, analog-to-digital converters, power converters, and switching MOSFETs, unintentionally mix the target audio with the attacker’s carrier.
The mixed signal is then re-radiated through wires, cables, and other components that effectively behave as accidental antennas. Researchers call the process an “Injection-Modulation-Emission” model.
The approach allows an attacker to select an effective injection frequency and force low-frequency secret signals, such as speech, onto a higher-frequency carrier that can travel much farther.
The team evaluated InjectEave against 11 commercial devices using an Ettus USRP B210 software-defined radio, log-periodic antennas, and a spectrum analyzer.
Targets included wired headphones from Sony, Dell, and Apple; wireless models from UGreen, Philips, and HP; a Flyingvoice VoIP landline phone; and smart lamps and fans.
At a 50-centimeter distance, researchers reported near-100% audio recognition across most tested headphone devices. Signal-to-noise ratios ranged from approximately 6 dB for Apple Earbuds to more than 23 dB for UGreen MAX2 wireless headphones.
With an external RF amplifier costing roughly $415, researchers increased transmission power from 18 dBm to 40 dBm.
This extended the practical audio-recovery distance for the UGreen MAX2 and Philips TAH2020 headphones to 30 meters while maintaining intelligible speech.
Physical barriers had limited impact. Glass and wood reduced signal strength by only 1 to 2 dB, while solid concrete caused about 5.8 dB of loss in headphone tests.
This creates potential risks for offices, hotels, meeting rooms, and other environments where attackers may operate outside the victim’s immediate space.

Researchers also demonstrated an “Eavesdrop-Synthesize-Inject” scenario against a Flyingvoice landline phone.
The attacker first recovered a victim’s voice, used trigger phrases such as “quote” or “confirmation” to activate an AI voice-cloning workflow, and injected synthetic audio back into a headset.
Arxiv stated that they used IndexTTS-2 for voice cloning and found that the injected speech closely resembled the original speaker.
Researchers also developed a diffusion-based denoising module that improved the quality of recovered audio, raising the signal-to-noise ratio from 7.0 dB to 16.1 dB and increasing speech intelligibility scores from 0.58 to 0.72.
The findings show that EM risks are not limited to high-speed digital interfaces. InjectEave targets continuous analog signals and hardware nonlinearities common across consumer electronics.
Standard cryptographic protections do not address this attack path, while conventional shielding may be overcome by stronger RF injection.
Teardown analysis found twisted-pair wiring could reduce leakage by up to 20 dB compared with parallel wiring.
However, the researchers said meaningful mitigation will require security-aware hardware and software co-design to reduce this newly exposed analog attack surface across headphones, phones, and IoT products.
Give your security team the visibility and context to investigate suspicious activity faster and contain threats before business impact grows. Strengthen Your Investigations with ANY.RUN