Article 78FDJ Researchers find way to listen in on headphones from afar

Researchers find way to listen in on headphones from afar

by
from www.theregister.com - Articles on (#78FDJ)
Story ImageResearchers based in China have devised a way to eavesdrop on signals handled by analog components in devices such as headphones, landline handsets, and smart devices by injecting electromagnetic (EM) signals. The technique, referred to as InjectEave, is not simply listening in on a low-frequency analog signal. It's an EM side-channel attack that overcomes one of the longstanding barriers to exploiting EM leakage: the faintness of RF signals in devices like headphones makes it difficult for adversarial listeners to separate signal from noise. Many different RF side-channel attacks have been explored, such as reading screen display emissions to reconstruct on-screen text or detecting the RF signals emitted by keys on a keyboard. But these techniques often prove impractical for passive EM capture because of the low signal-to-noise ratio. InjectEave trades passive signal capture for active signal manipulation. By transmitting a signal in the 0-9 MHz range - specifics have been withheld - an attacker can potentially modulate an otherwise difficult-to-detect audio signal so it can be captured by nearby equipment. "Our new project, InjectEave, shows that RF [radio frequency] signals can induce information leakage from everyday headphones, allowing an attacker to recover headphone audio from up to 30 meters away, including through walls," said Yan Long, assistant professor at The Hong Kong University of Science and Technology (HKUST) in Guangzhou, in an email to The Register. "We have verified the new vulnerability on multiple commercial devices including devices from Sony, HP, Philips, etc." Long and HKUST co-authors Haoran Yan, Ziyu Shao, and Shuhao Zhang, along with Qinhong Jiang of The Hong Kong Polytechnic University, describe their work in a paper [PDF] titled "Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware Nonlinearity," which was presented at USENIX Security 2026. The attack targets non-linear components found in computer systems, such as amplifiers, analog-to-digital converters, power converters, and switching MOSFETs. The interplay of the injected signals, the hardware, and the target audio signals essentially modulates the target signal so that it leaks and is detectable by the adversary. Conducting an InjectEave attack requires commodity RF equipment: a USRP B210 software-defined radio; antennas for injection and reception; a Siglent SSA3075X Plus spectrum analyzer; a laptop for controlling the SDR; and optionally an RF power amplifier to increase attack range. The researchers tested the technique with 11 off-the-shelf devices. One obvious application would be espionage, allowing an attacker to listen in on conversations carried over headphones or a landline phone. It could also be used to infer personal activities in households with smart fans or lamps through the monitoring and analysis of control signals and power consumption. Tested devices include: Sony ZX110AP (2014, wired headphones); Apple Earbuds (2016, wired earbuds); UGreen MAX2, Philips TAH2020, HP H231R (2024, 2025, 2023 wireless headphones); Flyingvoice P23GW (2023, VoIP landline); OIDIRE ODI-MF10A and Xiaomi BPLDS10DM (2023, 2025 smart fans); and JINGZAO JDO-06 and Xiaomi 1S (2024, 2019 smart lamps). "Our tests show that injection-induced side-channel attacks could eavesdrop on the majority of these devices from over 2m away and through walls, with a maximum distance of 30m for recovering intelligible headphone audio," the researchers state in their paper, noting that their tests indicate these scenarios are plausible in the wild. For the devices listed by the researchers, the maximum demonstrated attack range was generally between 1 and 6 meters, although they separately demonstrated headphone eavesdropping at up to 30 meters using an RF amplifier. Even so, the researchers documented various scenarios where eavesdropping could be done through hotel room walls and using attack hardware concealed in a nearby suitcase or within office furniture. The researchers note that non-linear components are common in computer systems and that any device with parts that handle signal stepping (e.g. power converters) may be vulnerable to InjectEave. "InjectEave is immune to digital defenses such as encryption, masking, and randomization, because the leakage comes from the analog path," the researchers conclude. "Hardware-aware mitigations such as twisted-pair wiring, shielding, and filtering can lower the energy that the injected carrier couples into the device, reducing the exposure. These mitigations raise the bar, but they do not guarantee immunity." (R)
External Content
Source RSS or Atom Feed
Feed Location http://www.theregister.co.uk/headlines.atom
Feed Title www.theregister.com - Articles
Feed Link https://www.theregister.com/
Reply 0 comments