Sony and Apple Headphones Vulnerable to Eavesdropping. Encryption Was Never Protecting Them

Researchers have discovered a way to recover audio from headphones without compromising the device itself, and there's little users can do to protect themselves.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

Researchers have found a new attack method called InjectEave, which could allow attackers to listen to private conversations played through both wireless and wired headphones, including models from Sony, Apple, HP, and Philips.[1]

The attackers don't need to hack into your headphones, Bluetooth connection, or even your phone, and encryption won't stop the attack. Researchers demonstrated the technique from up to 30 meters away, and they were also able to recover audio through a 30-centimeter concrete wall.

The attack requires specialist equipment and knowledge of the target device, but if successful, it could expose highly sensitive conversations without requiring any physical or software access to your headphones.

Here's how the attack works, the privacy risks it poses, and the steps you can take to protect yourself.

In this article
How InjectEave can eavesdrop on your headphones
How to protect sensitive calls from eavesdropping
The bottom line

How InjectEave can eavesdrop on your headphones

Researchers at the Hong Kong University of Science and Technology (Guangzhou) and Hong Kong Polytechnic University published a paper titled “Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware Nonlinearity” at USENIX Security 2026.

They used an attack method called InjectEave, which uses radio signals to recover audio from wired and wireless headphones, desk phones, and smart-home devices such as lamps and fans.

The researchers tested 11 commercial devices, including the Sony ZX110AP wired headphones, Apple Earbuds, UGreen MAX2 wireless headphones, Philips TAH2020, and HP H231R. They also tested a Flyingvoice VoIP phone, two smart fans, and two smart lamps.

They demonstrated the attack at distances ranging from around one to six meters, depending on the device. They also conducted through-wall demonstrations, placing the attacker about one meter from the target on the other side of a 30-centimeter concrete wall.

The researchers were also able to recover audio from up to 30 meters away, but that demonstration required an additional external RF power amplifier costing around $415.

It’s worth noting that encryption wouldn't help defend against InjectEave because the attack targets the analog signal after the audio has been decoded and converted into electrical signals, rather than the encrypted digital data.

The hidden wires carrying your audio

Usually, the audio playing through headphones is a weak, low-frequency electrical signal carried through wires. In wired headphones, this includes the cable running from the earpiece to the plug.

In wireless headphones, there are no external cables, but the devices still contain thin copper traces on their circuit boards and internal wires connecting different components.

Since these wires carry low-frequency signals, it wasn't always possible for an outsider to listen in on your communications. Earlier attacks that relied on electromagnetic leaks generally worked only from roughly half a meter to 1.5 meters away.

Injecting a radio signal into the headphones

Using InjectEave, an attacker can transmit a steady radio signal toward the device, which can be picked up by the wires inside the headphones. These wires aren't designed to work as antennas, but any piece of metal can pick up radio waves. This allows them to behave like antennas even when they weren't designed to do so.

The headphone's wiring picks up the radio signal and carries it to a chip inside the device, where it interacts with the audio. This effectively puts the audio onto the radio carrier, similar to how speech rides on an AM radio signal.

How the headphones mix the signals

This happens because components inside electronic devices aren't perfectly linear. If they were, two signals passing through them wouldn't interact with each other in this way. Because these components are nonlinear, however, they can mix the signals together.

In the headphones tested by the researchers, the vulnerable component was the amplifier. Other devices leaked through different components, including ADCs and amplifiers in landline phones, switching MOSFETs in smart fans, and power converters in smart lamps.

Once this happens, the wire carries a high-frequency signal that can radiate outside the device. An attacker's antenna can pick it up, and a spectrum analyzer can demodulate it back into audio.

Cleaning up the recovered audio

The researchers then used a speech-cleaning model called SGMSE. It’s a diffusion model that can clean noisy recordings and make the recovered speech easier to understand. This is necessary because the mixing process also creates unwanted tones and distortions that become intermingled with human speech.

In one test, SGMSE improved the signal-to-noise ratio from 7.0 to 16.1 dB and the intelligibility score (STOI) from 0.58 to 0.72, although the researchers still recorded a word error rate of around 22%.

How to protect sensitive calls from eavesdropping

This isn't a mass-surveillance technique, like how Flock cameras are. The attacker needs specialist RF equipment, the exact device model, the appropriate injection frequency, as well as carefully positioned antennas. The researchers also found that different headphone models respond to different frequencies.

Still, there isn't much an ordinary headphone user can do to eliminate the risk of InjectEave.

The researchers identified hardware-level defenses such as twisted-pair wiring, shielding, and filtering, but these are primarily mitigations that manufacturers can build into devices rather than settings you can enable yourself. Also, while they can reduce the leakage, they don't guarantee immunity.

As for what you can actually do, if you're discussing financial information, business negotiations, passwords, or other sensitive details, take the call in a closed space where an attacker would have a harder time positioning themselves close to you or otherwise intercepting the conversation.

The researchers also found that leakage becomes stronger at higher playback volumes. Lowering the volume may therefore make the attack harder, but it still doesn't stop it outright.

All these small steps matter because, while the attack is relatively difficult to pull off, a successful interception could have serious consequences depending on what you're discussing.

If you're giving someone your credit card details over a call, for example, an attacker could potentially capture that information and use it for financial fraud. Conversations about upcoming purchases, account details, or personal information could also give attackers material for convincing phishing attacks or identity theft.

The bottom line

InjectEave shows that attackers don't always need to compromise your phone, Bluetooth connection, or headphones to intercept your sensitive audio. By injecting a radio signal and exploiting nonlinear components inside the device, researchers were able to turn otherwise weak electromagnetic leakage into a recoverable audio signal.

The good news is that this remains a highly targeted attack requiring specialist equipment and knowledge of the specific device. The researchers' demonstrations don't mean someone can casually sit nearby with a laptop and listen to your headphones.

For now, the simplest precaution is to treat highly sensitive conversations differently from ordinary calls. Take them in controlled environments, avoid discussing passwords or payment details where someone could potentially overhear you, and don't assume that encryption alone can protect the analog audio coming out of your device.

4.8
Editorial Rating
Claim Deal
On Aura Identity Theft's website
2026 Editors’ Choice
Best Overall Identity Theft Protection Service
Identity Protection
Aura Identity Theft
PROMOTION: Save Up to 68%
  • ID theft protection that monitors your SSN, bank accounts, credit cards, and brokerage and retirement accounts for suspicious activity
  • Every plan includes the full feature set, so no additional cost to unlock monitoring, insurance, or restoration
  • Bundles data removal with identity theft protection, antivirus, VPN, and a password manager in one subscription

Author Details
Krishi Chowdhary specializes in digital privacy, cybersecurity, and consumer technology. He has written extensively on online privacy tools and broader cybersecurity topics, including online scams, data breaches, age verification, and emerging digital threats. Krishi believes technology reporting should empower readers, not confuse them, and is committed to making even the most technical subjects easy to understand without compromising on accuracy or depth. His work has appeared in leading technology publications, including CNET, ExpressVPN, and TechRadar, where he has covered topics ranging from cybersecurity incidents and privacy product announcements to artificial intelligence and major technology news

Citations

[1] Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware Nonlinearity