Researchers Listen To Headphones From 30 Metres Away

Researchers Listen To Headphones From 30 Metres Away

Researchers have demonstrated a way to recover audio playing through headphones from up to 30 metres away, revealing how confidential conversations could leak through everyday electronics even when the software carrying them uses encryption.

How Does The Attack Work?

The technique, called InjectEave, was developed by researchers at the Hong Kong University of Science and Technology in Guangzhou and Hong Kong Polytechnic University, with their findings presented at the USENIX Security 2026 conference.

Rather than intercepting a Bluetooth connection or installing malware, the attacker transmits a radio signal towards the device. Inside vulnerable electronics, components such as amplifiers unintentionally mix that signal with the electrical signals carrying audio, producing emissions that nearby receiving equipment can capture and turn back into speech.

Ordinarily, these audio signals are too weak to recover easily from a distance, but the injected signal makes them easier to detect. The researchers also use an AI-based speech enhancement system to reduce distortion and background noise in the recovered audio.

As the project website explains, “InjectEave does not exploit wireless-communication vulnerabilities such as WiFi or Bluetooth”, which means changing connection settings does not necessarily address the underlying weakness.

What Did The Researchers Test?

The team reports evaluating 11 commercial devices across categories including wired headphones, wireless headphones, a landline telephone, smart fans and smart lamps. Listed audio products include Sony ZX110AP headphones, Apple wired earbuds and models from UGreen, Philips and HP.

These were tests on particular devices, rather than evidence that every product from those manufacturers is vulnerable. The researchers conducted their evaluations without modifying the target equipment or requiring physical access to it.

For headphones, the information recovered was audio being played to the wearer. This matters because listening privately to a customer call, recorded meeting or confidential briefing could expose information without anyone nearby being able to hear the headphones normally.

The work also examined microphone signals, but those experiments achieved a much shorter range of approximately 30 centimetres, so the headline distance should not be interpreted as an ability to capture every conversation happening around a headset.

How Far Away Could Someone Listen?

The published device table shows maximum distances ranging from one to six metres under the main test conditions. To reach 30 metres with UGreen and Philips headphones, the researchers added an external radio-frequency power amplifier.

Through-wall demonstrations were separate, including one involving a distance of one metre through a 30-centimetre concrete wall. Other demonstrations recreated hotel and meeting-room settings, illustrating why closing a door does not necessarily block this type of signal.

However, it should be noted here that these results really depend on equipment, positioning, transmission power and the target device, rather than providing a guaranteed listening range. The attack also requires dedicated transmitting and receiving hardware, antennas and a controlling computer, making it a different proposition from downloading an ordinary phone app.

Why Encryption Doesn’t Stop It

Encryption protects information while it travels between systems, but a headphone eventually needs an electrical audio signal to produce sound. InjectEave targets that part of the process, after the information has become usable audio.

The researchers describe the limitation clearly, saying “the leakage comes from the analog path”, meaning the physical circuitry handling signals rather than the protected digital connection.

That doesn’t make encryption pointless, because it still protects against other forms of interception. Instead, the findings show why secure communications also depend on the equipment used at either end, particularly where conversations contain commercially sensitive information.

Could Other Devices Leak Information?

The wider research extends beyond listening to speech, with tests showing that signals from, e.g., smart fans and lamps could reveal operating speed or brightness. Those readings could potentially support inferences about household routines, although they do not directly prove what somebody is doing.

A separate landline demonstration combined recovered conversation audio with synthesised speech injected into the telephone’s output, showing how the technique could potentially support deception as well as surveillance.

That said, these are still just research demonstrations, and the published findings don’t establish that criminals are already deploying InjectEave against businesses.

What Does This Mean For Your Business?

For businesses handling confidential conversations, the findings provide a reason to consider physical surroundings as well as secure calling software. Sensitive discussions in hotels, shared offices or rooms beside publicly accessible areas deserve particular attention, although this research alone doesn’t justify replacing every headset. A more proportionate response would perhaps begin by identifying which conversations would cause serious harm if overheard.

Organisations with stronger confidentiality requirements should ask equipment suppliers about protection against electromagnetic interference and seek specialist advice where necessary. The researchers identify shielding, filtering and changes to wiring as ways to reduce exposure, while warning that “These mitigations raise the bar, but they don’t guarantee immunity.” Ordinary software updates should therefore not be presented as a confirmed fix for this hardware problem.

The practical lesson here is to match protection to the sensitivity of the work, combining suitable equipment with controlled meeting spaces and clear procedures for confidential calls. Encryption remains essential, but the privacy of a conversation ultimately depends on the whole route from the person speaking to the device delivering their words.