Researchers in China have developed a novel technique called InjectEave that allows adversaries to eavesdrop on analog components in devices like headphones and smart appliances from up to 30 meters away, according to a paper presented at USENIX Security 2026. By actively injecting electromagnetic signals into targeted hardware, the method overcomes traditional barriers of passive signal capture.
How InjectEave Performs Active Electromagnetic Injection
According to the research team from The Hong Kong University of Science and Technology (HKUST) in Guangzhou and The Hong Kong Polytechnic University, passive radio frequency (RF) side-channel attacks often fail due to low signal-to-noise ratios. InjectEave addresses this by trading passive capture for active signal manipulation. The technique transmits a carrier signal in the 0–9 MHz range to interact with non-linear hardware components inside everyday tech, such as power converters, amplifiers, analog-to-digital converters, and switching MOSFETs.
This interaction modulates target audio or control signals so they leak and can be captured by an adversary. As assistant professor Yan Long of HKUST explained in an email to The Register, the approach allows attackers to recover headphone audio through walls and from a distance of up to 30 meters when using an RF power amplifier.
Hardware Vulnerable to InjectEave Attacks
The research team tested 11 off-the-shelf commercial devices and verified the vulnerability across multiple brands. According to findings published in their USENIX Security 2026 paper, tested equipment includes wired and wireless headphones, VoIP landlines, and smart home appliances produced between 2014 and 2025.
Specific hardware models tested by the researchers include:
- Headphones: Sony ZX110AP (2014), Apple Earbuds (2016), UGreen MAX2 (2024), Philips TAH2020 (2025), and HP H231R (2023).
- Landlines: Flyingvoice P23GW VoIP landline (2023).
- Smart Devices: OIDIRE ODI-MF10A smart fans (2023), Xiaomi BPLDS10DM smart fans (2025), JINGZAO JDO-06 smart lamps (2024), and Xiaomi 1S smart lamps (2019).
Without an RF amplifier, the maximum demonstrated attack range for these devices typically ranged between 1 and 6 meters, proving that eavesdropping scenarios are plausible in real-world environments like hotel rooms or adjacent offices.
Did you know? InjectEave requires commodity equipment that is readily available to researchers and potential attackers alike, including a USRP B210 software-defined radio, antennas, a Siglent SSA3075X Plus spectrum analyzer, and a laptop.
Limitations of Digital Defenses Against Analog Leaks
Because the leakage originates entirely within the analog path of vulnerable hardware, the researchers concluded that InjectEave is immune to traditional digital defenses such as encryption, masking, and randomization.

Mitigating this vulnerability requires physical, hardware-aware changes. Measures like twisted-pair wiring, electromagnetic shielding, and specialized filtering can lower the energy that an injected carrier couples into a device. However, the researchers note that while these interventions raise the bar for attackers, they do not guarantee complete immunity.
Frequently Asked Questions
What is an InjectEave attack?
InjectEave is an active electromagnetic side-channel attack that injects RF signals into everyday devices to modulate and extract internal audio or control signals through hardware nonlinearity.
Can software updates fix InjectEave?
No. According to the researchers, software patches, encryption, and digital masking cannot stop the attack because the signal leakage stems directly from physical analog components.
What equipment is needed to execute this attack?
Attackers utilize commodity RF hardware, including a USRP B210 software-defined radio, a spectrum analyzer, antennas for transmission and reception, and optionally an RF power amplifier to extend the range.
What are your thoughts on hardware-level side-channel vulnerabilities? Share your perspective in the comments below, or subscribe to our newsletter for more cybersecurity updates.
Related reading