InjectEave Attack Recovers Headphone Audio From 30 Meters, Bypassing Encryption
Researchers from HKUST (Guangzhou) and Hong Kong Polytechnic University demonstrated InjectEave, an attack that makes analog components in consumer headphones re-radiate the audio they play. With a USRP B210 and a ~$400 RF amplifier, intelligible audio was recovered through walls at up to 30 meters; 11 devices were tested, including Sony ZX110AP and Philips TAH2020.
- The attack exploits the analog signal path, so encryption, masking and randomization offer no protection
- Entry-level radio gear reads audio at 1–6 meters through walls; a low-cost amplifier extends range to 30 meters
- 11 products tested, including Sony ZX110AP, Apple wired earbuds, UGreen MAX2, Philips TAH2020 and HP H231R
- Mitigations include EM shielding, RF filtering and twisted-pair headphone wiring, but none eliminate the risk
Read next
Security