Researchers have uncovered a hardware-level cybersecurity vulnerability dubbed InjectEave, which allows attackers to remotely eavesdrop on wired and wireless headphones, VoIP landlines, and smart home appliances from up to 30 meters away. According to a threat intelligence report presented at the USENIX Security conference, the active electromagnetic side-channel attack exploits non-linear analog components in commercial devices manufactured between 2014 and 2025.
How the InjectEave Side-Channel Attack Works
InjectEave operates as an active electromagnetic side-channel attack rather than passive sniffing, which frequently fails due to low signal-to-noise ratios. According to research findings, the attack works by injecting a specific electromagnetic carrier signal ranging from 0 to 9 MHz directly into a target device. This injected signal interacts with non-linear hardware components inside the device, including power converters, amplifiers, analog-to-digital converters, and MOSFETs that lack sufficient electromagnetic shielding.
Through hardware nonlinearity, the device’s internal audio or control signals are modulated onto the injected carrier wave. This up-converted signal is then re-radiated outward, allowing an attacker stationed nearby to capture and demodulate sensitive private conversations or monitor smart home activity.
Vulnerable Hardware Models and Tested Devices
The vulnerability impacts a wide range of analog and digital devices containing vulnerable commercial components. According to the research team’s technical documentation, laboratory testing successfully demonstrated the attack on multiple specific hardware models:

- Headphones: Sony ZX110AP, Apple Earbuds, UGreen MAX2, Philips TAH2020, and HP H231R.
- Landlines: Flyingvoice P23GW VoIP landline systems.
- Smart Devices: Xiaomi BPLDS10DM/1S, OIDIRE ODI-MF10A, and JINGZAO JDO-06.
Required Attack Equipment and Exploitation Complexity
Executing an InjectEave attack requires specialized radio frequency knowledge and targeted hardware setups. According to technical exploitation breakdowns, the attack vector is classified as adjacent, meaning signals can penetrate interior walls. With signal amplification, the effective operational range extends up to 30 meters.
Researchers utilized specific hardware tools during testing, including a USRP B210 Software Defined Radio (SDR), dedicated antennas for signal injection and reception, a Siglent SSA3075X Plus spectrum analyzer, and an RF Power Amplifier used to extend the transmission range.
Mitigation and Hardware Design Challenges
Traditional software patches cannot resolve the flaw because InjectEave targets the fundamental physics of analog hardware components. According to remediation analyses, protecting devices against this vector requires fundamental hardware redesigns. Effective workarounds and long-term manufacturing solutions include implementing high-quality shielding, adding signal filters, utilizing twisted-pair wiring to reduce electromagnetic coupling, and storing sensitive audio devices inside Faraday-style pouches when not actively in use.
Related reading