All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
Researchers have found a new attack method called InjectEave, which could allow attackers to listen to private conversations played through both wireless and wired headphones, including models from Sony, Apple, HP, and Philips.[1]
The attackers don't need to hack into your headphones, Bluetooth connection, or even your phone, and encryption won't stop the attack. Researchers demonstrated the technique from up to 30 meters away, and they were also able to recover audio through a 30-centimeter concrete wall.
The attack requires specialist equipment and knowledge of the target device, but if successful, it could expose highly sensitive conversations without requiring any physical or software access to your headphones.
Here's how the attack works, the privacy risks it poses, and the steps you can take to protect yourself.
How to protect sensitive calls from eavesdropping
The bottom line
How InjectEave can eavesdrop on your headphones
Researchers at the Hong Kong University of Science and Technology (Guangzhou) and Hong Kong Polytechnic University published a paper titled “Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware Nonlinearity” at USENIX Security 2026.
They used an attack method called InjectEave, which uses radio signals to recover audio from wired and wireless headphones, desk phones, and smart-home devices such as lamps and fans.
The researchers tested 11 commercial devices, including the Sony ZX110AP wired headphones, Apple Earbuds, UGreen MAX2 wireless headphones, Philips TAH2020, and HP H231R. They also tested a Flyingvoice VoIP phone, two smart fans, and two smart lamps.
They demonstrated the attack at distances ranging from around one to six meters, depending on the device. They also conducted through-wall demonstrations, placing the attacker about one meter from the target on the other side of a 30-centimeter concrete wall.
The researchers were also able to recover audio from up to 30 meters away, but that demonstration required an additional external RF power amplifier costing around $415.
It’s worth noting that encryption wouldn't help defend against InjectEave because the attack targets the analog signal after the audio has been decoded and converted into electrical signals, rather than the encrypted digital data.
The hidden wires carrying your audio
Usually, the audio playing through headphones is a weak, low-frequency electrical signal carried through wires. In wired headphones, this includes the cable running from the earpiece to the plug.
In wireless headphones, there are no external cables, but the devices still contain thin copper traces on their circuit boards and internal wires connecting different components.
Since these wires carry low-frequency signals, it wasn't always possible for an outsider to listen in on your communications. Earlier attacks that relied on electromagnetic leaks generally worked only from roughly half a meter to 1.5 meters away.
Injecting a radio signal into the headphones
Using InjectEave, an attacker can transmit a steady radio signal toward the device, which can be picked up by the wires inside the headphones. These wires aren't designed to work as antennas, but any piece of metal can pick up radio waves. This allows them to behave like antennas even when they weren't designed to do so.
The headphone's wiring picks up the radio signal and carries it to a chip inside the device, where it interacts with the audio. This effectively puts the audio onto the radio carrier, similar to how speech rides on an AM radio signal.
How the headphones mix the signals
This happens because components inside electronic devices aren't perfectly linear. If they were, two signals passing through them wouldn't interact with each other in this way. Because these components are nonlinear, however, they can mix the signals together.
In the headphones tested by the researchers, the vulnerable component was the amplifier. Other devices leaked through different components, including ADCs and amplifiers in landline phones, switching MOSFETs in smart fans, and power converters in smart lamps.
Once this happens, the wire carries a high-frequency signal that can radiate outside the device. An attacker's antenna can pick it up, and a spectrum analyzer can demodulate it back into audio.
Cleaning up the recovered audio
The researchers then used a speech-cleaning model called SGMSE. It’s a diffusion model that can clean noisy recordings and make the recovered speech easier to understand. This is necessary because the mixing process also creates unwanted tones and distortions that become intermingled with human speech.
In one test, SGMSE improved the signal-to-noise ratio from 7.0 to 16.1 dB and the intelligibility score (STOI) from 0.58 to 0.72, although the researchers still recorded a word error rate of around 22%.
How to protect sensitive calls from eavesdropping
This isn't a mass-surveillance technique, like how Flock cameras are. The attacker needs specialist RF equipment, the exact device model, the appropriate injection frequency, as well as carefully positioned antennas. The researchers also found that different headphone models respond to different frequencies.
Still, there isn't much an ordinary headphone user can do to eliminate the risk of InjectEave.
The researchers identified hardware-level defenses such as twisted-pair wiring, shielding, and filtering, but these are primarily mitigations that manufacturers can build into devices rather than settings you can enable yourself. Also, while they can reduce the leakage, they don't guarantee immunity.
As for what you can actually do, if you're discussing financial information, business negotiations, passwords, or other sensitive details, take the call in a closed space where an attacker would have a harder time positioning themselves close to you or otherwise intercepting the conversation.
The researchers also found that leakage becomes stronger at higher playback volumes. Lowering the volume may therefore make the attack harder, but it still doesn't stop it outright.
All these small steps matter because, while the attack is relatively difficult to pull off, a successful interception could have serious consequences depending on what you're discussing.
If you're giving someone your credit card details over a call, for example, an attacker could potentially capture that information and use it for financial fraud. Conversations about upcoming purchases, account details, or personal information could also give attackers material for convincing phishing attacks or identity theft.
The bottom line
InjectEave shows that attackers don't always need to compromise your phone, Bluetooth connection, or headphones to intercept your sensitive audio. By injecting a radio signal and exploiting nonlinear components inside the device, researchers were able to turn otherwise weak electromagnetic leakage into a recoverable audio signal.
The good news is that this remains a highly targeted attack requiring specialist equipment and knowledge of the specific device. The researchers' demonstrations don't mean someone can casually sit nearby with a laptop and listen to your headphones.
For now, the simplest precaution is to treat highly sensitive conversations differently from ordinary calls. Take them in controlled environments, avoid discussing passwords or payment details where someone could potentially overhear you, and don't assume that encryption alone can protect the analog audio coming out of your device.