Ethical Hacking News
A new technique called InjectEave has been developed, which enables the eavesdropping of signals handled by analog components in devices such as headphones, landline handsets, and smart devices. According to researchers based in China, the technique involves injecting electromagnetic signals into devices and manipulating the hardware to induce side-channel leakage, allowing attackers to recover sensitive information. The InjectEave technique has been demonstrated on a range of commercial devices, including those from Sony, HP, Philips, and Apple, and has been shown to be effective in recovering intelligible audio signals from devices up to 30 meters away, even through walls. The implications of the InjectEave technique are significant, and highlight the need for greater awareness and vigilance in the development and deployment of devices that contain analog components.
InjectEave is a new technique that enables eavesdropping of signals from devices with analog components. The technique involves injecting electromagnetic signals into devices and manipulating hardware to induce side-channel leakage. Attackers can recover sensitive information, such as audio signals, from devices even when they are not actively being used. The technique has been demonstrated on a range of commercial devices, including those from Sony, HP, Philips, and Apple. The implications are significant, highlighting the need for greater awareness and vigilance in device development and deployment.
A recent breakthrough in the field of electromagnetic interference (EMI) security has shed new light on the vulnerabilities of everyday devices that can be exploited by malicious actors. According to researchers based in China, a new technique known as InjectEave has been developed, which enables the eavesdropping of signals handled by analog components in devices such as headphones, landline handsets, and smart devices.
The technique, which was presented at the USENIX Security 2026 conference, involves injecting electromagnetic signals into devices and manipulating the hardware to induce side-channel leakage. This allows attackers to recover sensitive information, such as audio signals, from devices, even when they are not actively being used.
The researchers, led by Yan Long, assistant professor at The Hong Kong University of Science and Technology (HKUST), have demonstrated the effectiveness of the InjectEave technique on a range of commercial devices, including those from Sony, HP, Philips, and Apple. Their tests showed that the technique can recover intelligible audio signals from devices up to 30 meters away, even through walls.
The researchers' approach to the problem is different from traditional radio frequency (RF) side-channel attacks, which often rely on passive signal capture. Instead, InjectEave involves active signal manipulation, which enables the eavesdropping of signals from devices without the need for specialized equipment.
The technique is not limited to headphones and landline handsets, but can also be applied to other devices with non-linear components, such as amplifiers, analog-to-digital converters, power converters, and switching MOSFETs. The researchers have demonstrated the effectiveness of InjectEave on a range of devices, including smart fans and smart lamps.
Conducting an InjectEave attack requires commodity RF equipment, including a software-defined radio, a spectrum analyzer, and a laptop for controlling the SDR. The researchers have also noted that hardware-aware mitigations, such as twisted-pair wiring, shielding, and filtering, can lower the energy that the injected carrier couples into the device, reducing the exposure.
The implications of the InjectEave technique are significant, and highlight the need for greater awareness and vigilance in the development and deployment of devices that contain analog components. As the use of devices with non-linear components becomes more widespread, the risk of electromagnetic interference vulnerabilities will also increase.
The researchers' findings have been published in a paper titled "Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware Nonlinearity," which was presented at the USENIX Security 2026 conference.
Related Information:
https://www.ethicalhackingnews.com/articles/InjectEave-A-New-Class-of-Electromagnetic-Interference-Vulnerabilities-in-Everyday-Devices-ehn.shtml
https://www.theregister.com/security/2026/09/17/researchers-find-way-to-listen-in-on-headphones-from-afar/5297303
Published: Thu Sep 17 15:08:23 2026 by llama3.2 3B Q4_K_M