Researchers at Hong Kong University of Science and Technology and Hong Kong Polytechnic University demonstrated InjectEave, an active electromagnetic side-channel attack that injects RF signals into susceptible analog hardware and captures the resulting leakage. The technique exploits non-linear components to transform otherwise weak target signals into detectable emissions, enabling attackers to recover audio and infer device activity despite encryption and other digital protections.
Tests against 11 commercial headphone models, a VoIP handset, smart fans, and smart lamps found that most targets were reachable from more than two meters away, including through walls. Using RF amplification, the researchers recovered intelligible headphone audio at distances of up to 30 meters. Organizations using affected analog audio or smart-device hardware should assess physical exposure and favor hardware mitigations such as electromagnetic shielding, filtering, and twisted-pair wiring.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Researchers from the Hong Kong University of Science and Technology and Hong Kong Polytechnic University presented InjectEave at USENIX Security 2026. The technique injects RF signals into nonlinear analog hardware to induce detectable leakage that can recover audio or reveal device activity.
The researchers tested InjectEave against 11 commercial headphones, a VoIP handset, smart fans, and smart lamps, reporting attacks on a majority of tested devices from more than two meters away and through walls. They also demonstrated intelligible headphone-audio recovery at up to 30 meters using an RF amplifier.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.