Cyber Security

Your encrypted call can still leak after it reaches your headphones

IT Club Editorial8 minutes read25 September 2026
WhatsAppEmail
Your encrypted call can still leak after it reaches your headphones

Keep up with IT Club

Add IT Club as a preferred source in Google Search.

USENIX Security '26 research recovered audio from wired and wireless headphones by injecting an RF carrier and exploiting nonlinear analogue hardware. The reported 30-metre maximum used specialised experimental conditions; ordinary commercial-device results were about 1–6 metres, and a separate through-wall demonstration was at 1 metre through 30 cm of concrete.

Encryption can protect a call while it travels across the internet. It cannot automatically protect every physical signal produced after the endpoint decrypts that call so a person can hear it.

That is the useful lesson from InjectEave, the name given to research presented in “Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware Nonlinearity” at USENIX Security '26. It is an unusual electromagnetic side-channel result, not a reason to assume that somebody is routinely parked outside an office listening to every Teams call.

What did the researchers recover?

The researchers demonstrated recovering audio played through commercial wired and wireless headphones. Their work also examined other low-frequency analogue information, including smart-fan speed, smart-lamp brightness and landline audio. In audio demonstrations, signal processing and optional speech enhancement helped make recovered speech intelligible.

The result is not “encryption is useless”. The researchers did not crack a call or read its encrypted network traffic. They measured a physical leakage path after the endpoint had already turned protected data into an analogue signal.

How InjectEave works

A transmitter sends an RF carrier towards the target. Nonlinear components such as amplifiers, analogue-to-digital converters, switching devices and power converters can mix that carrier with a low-frequency secret signal. The audio is effectively shifted onto sidebands around the carrier, where an attacker can receive it, demodulate it and optionally enhance it.

The evaluation used a transmitting antenna, a receiving antenna and RF measurement equipment. The researchers reported no physical access or hardware or software modification in their commercial-device evaluation. This is an analogue hardware phenomenon, not a Wi-Fi or Bluetooth vulnerability.

The 30-metre headline needs context

The USENIX abstract reports eavesdropping on wired and wireless headphone audio from up to 30 metres with accessible RF equipment. That is a maximum experimental result, not a normal operating range or a promise that any headphones can be heard from that distance.

The project details list ordinary commercial-device demonstrations at roughly 1–6 metres: for example, 5 metres for a Sony wired headphone, 1 metre for Apple earbuds and 6 metres for a UGreen wireless headphone. The longer-range result required carefully arranged conditions and a stronger, lower-noise, more directional RF setup than the basic equipment. Distance depends on the device, carrier, antennas, power, noise, alignment and surroundings.

Through a wall does not mean 30 metres through a wall

Through-wall testing was demonstrated separately. The project describes an attacker in an adjacent room recovering audio at 1 metre through a 30 cm concrete wall, as well as hotel-room and meeting-room case studies. That supports the narrower statement that through-wall leakage was tested under specified conditions. It does not support a 30-metre through-wall claim.

What should an SME do?

Do not let an exotic endpoint side channel distract from much more likely attacks. Keep prioritising phishing-resistant sign-in, MFA, supported devices, patching, strong account recovery and protection against stolen credentials. Do not treat this research as evidence that ordinary headphones need an emergency replacement.

The research is still valuable for businesses with unusually sensitive conversations, industrial systems or high-value intellectual property. Those organisations may need to discuss device selection, wired layouts, shielding, filtering, physical room security, meeting location and specialist electromagnetic protections. Encryption is one layer, not a force field around the computer.

The IT Club view

Security does not end when data reaches the endpoint. A sensible risk assessment asks what the endpoint emits, what an attacker would need, how close they would need to be and whether the information is valuable enough to justify specialist controls. For most SMEs, that produces sensible priorities without dismissing an important research result.

Sources and further reading

USENIX Security '26: Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware Nonlinearity →

InjectEave project site: demonstrations, equipment and affected-device results →

Plain-English Takeaway

Encryption remains essential, but it protects data in transit rather than every physical signal at the endpoint. For most SMEs, phishing and stolen credentials are more urgent; highly sensitive environments may additionally consider hardware, room and electromagnetic leakage.

Frequently asked questions

Did InjectEave crack an encrypted call?

No. The technique targets analogue hardware after the endpoint has received and decrypted audio. It induces and measures electromagnetic leakage; it does not decrypt the network traffic or break the encryption.

Can anyone listen to headphones from 30 metres away?

That is not a fair interpretation. The paper reports a maximum of up to 30 metres with accessible RF equipment, while the project's ordinary commercial-device results were about 1–6 metres. The maximum required specialised experimental equipment, alignment and conditions.

Was the attack tested through a wall?

Yes, separately from the 30-metre result. The project describes a demonstration at 1 metre through a 30 cm concrete wall, plus hotel- and meeting-room case studies. It does not establish a 30-metre through-wall capability.

Should a small business replace its headphones?

Usually not because of this research alone. Prioritise ordinary controls such as phishing resistance, MFA, patching and credential protection. Organisations handling exceptionally sensitive information can discuss endpoint hardware, room location and physical or electromagnetic controls with a specialist.

Enjoyed this article?

Follow The IT Club Briefing on WhatsApp for short daily technology updates and practical business insights.

Have a question we should answer?

Ask the IT Club Advisor