An eavesdropping technique that captures sound played through headphones as electromagnetic signals from outside has been disclosed. Researchers said it does not hack Bluetooth communication but instead uses signals that leak from internal circuits, making it hard to block through encryption alone.
On Sept. 21 local time, IT outlet TechRadar reported that researchers from the Guangzhou campus of the Hong Kong University of Science and Technology and the Hong Kong Polytechnic University presented a technique called InjectEave at the security conference USENIX Security 2026. The researchers tested 11 commercially available devices and reconstructed playback from wired and wireless headphones, call audio from wired telephones and the operating status of some smart home devices.
The principle is to transmit radio waves to a target device from outside. When nonlinear circuits inside the device, such as amplifiers or power converters, load the injected radio waves with the audio signal being played, it becomes possible to receive electromagnetic signals re-emitted from wiring and cables and reconstruct the audio. Because it targets analog circuitry after the sound has been decrypted, it is a separate issue from Bluetooth communication encryption.
The researchers said they reconstructed voices through a wall and could make out headphone audio from as far as 30 metres away. The 30-metre result, however, came under conditions that used a high-power 10-watt transmitter continuously. In typical tests, they captured signals from about 1 to 6 metres away depending on the device, and reconstructing actual human speech clearly is more difficult than using test signals. The through-the-wall test and the maximum-distance test were also not conducted under the same conditions.
There are also differences in what information can be eavesdropped. With wireless headphones, the sound a user listens to can be captured, but the researchers did not capture what the user says into the microphone. With wired headsets, they confirmed the possibility of leakage from microphone input signals, but the detection distance was short. An attacker must analyse a device of the same model as the target in advance.
The researchers notified manufacturers of the vulnerabilities and excluded some attack-related information from public code. They said hardware measures such as shielding and filtering can reduce exposure but do not guarantee complete defence. The study is based on test results targeting some devices and does not mean all headphones can be eavesdropped on from beyond 30 metres.