Researchers at the Hong Kong University of Science and Technology (Guangzhou) and Hong Kong Polytechnic University disclosed InjectEave, an active electromagnetic side-channel technique that recovers audio played through wired and wireless headphones from up to 30 meters away, including through concrete walls. Instead of relying on weak passive emissions, an attacker transmits a tuned RF carrier that nonlinear components—such as amplifiers, ADCs, and power converters—mix with low-frequency audio signals, causing the audio to be re-emitted on a measurable carrier; the demonstrations used commercially available SDR equipment.
The researchers also observed injection-induced leakage from smart-home power consumption and analog sensor inputs. In a closed-loop scenario involving a Flyingvoice VoIP landline, they combined eavesdropping with AI voice cloning and synthesized-audio injection, demonstrating both confidentiality and integrity risks. The findings identify analog circuitry and connected-device wiring as an attack surface that can bypass protections aimed at digital communications and may not be fully addressed by conventional cryptography or ordinary EM shielding.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
Haoran Yan, Ziyu Shao, Shuhao Zhang, Qinhong Jiang, and Yan Long submitted a paper introducing Injection-Induced EM Side Channels and the InjectEave attack. The research demonstrated RF-injection-assisted recovery of headphone audio at up to 30 meters, including through-wall scenarios, and described smart-device and landline-phone leakage and manipulation risks.
The paper "Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware Nonlinearity" was accepted at USENIX Security '26. The reported work tested the attack against commercial headphones, a Flyingvoice VoIP landline, and smart devices, including a closed-loop eavesdrop-synthesize-inject demonstration against the landline.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourcearxiv.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.