Category: Cyber Security | Published: 2026-09-25
Can someone listen to my headphones even when nobody nearby can hear the sound? Security researchers have demonstrated that audio playing through some commercial headphones can be recovered from a distance by using specially designed radio equipment.
The technique, called InjectEave, does not break a Bluetooth connection, guess a password or install malware on the target device. Instead, it takes advantage of unintended electromagnetic behaviour inside vulnerable electronics.
The research is significant because it shows that a private call or confidential recording can potentially leak after encrypted data has already reached the headphones. It does not mean that every pair of headphones can be monitored from 30 metres away or that an ordinary phone app can perform the attack.
What Is InjectEave?
InjectEave was developed by researchers at the Hong Kong University of Science and Technology in Guangzhou and Hong Kong Polytechnic University. Their findings were presented at the USENIX Security 2026 conference.
The attack begins with a radio signal transmitted towards the target equipment. Inside some devices, components such as amplifiers can unintentionally mix that injected signal with the electrical signal carrying the audio.
This interaction creates emissions that receiving equipment can detect. The attacker can then process those emissions and attempt to reconstruct the speech or sound being delivered to the headphones.
Audio signals that escape from electronics are normally too weak or distorted to recover easily at a useful distance. The injected radio signal makes the leakage easier to identify. The researchers also used an AI-based speech enhancement system to reduce noise and improve the intelligibility of the recovered audio.
The project specifically states that InjectEave does not exploit Wi-Fi or Bluetooth communication vulnerabilities. Turning off Bluetooth features that are not in use is still sensible security practice, but it does not directly address the analogue weakness demonstrated in this research.
Can Someone Listen to My Headphones From 30 Metres Away?
The careful answer is that researchers achieved a 30-metre result with particular headphone models and additional radio-frequency amplification. That result should not be treated as the normal range for every device or environment.
In the published device table, maximum distances under the main test conditions ranged from one to six metres. The team reached 30 metres with UGreen and Philips headphones after adding an external radio-frequency power amplifier.
The achievable distance depends on the target device, the attacker's equipment, antenna placement, transmission power, local interference and the physical environment. A result obtained under research conditions does not guarantee that the same range will be possible in an office, hotel or home.
The attack also needs dedicated transmitting and receiving hardware, antennas and a controlling computer. This is a specialist technical setup rather than something a casual attacker can perform by downloading an app.
So, can someone listen to your headphones? The research shows that it can be technically possible with vulnerable equipment and the right specialist hardware. It does not show that every headset is exposed or that this is currently a common form of criminal surveillance.
Which Devices Did the Researchers Test?
The team evaluated 11 commercial devices across several categories. These included wired headphones, wireless headphones, a landline telephone, smart fans and smart lamps.
The listed audio products included Sony ZX110AP headphones, Apple wired earbuds and models from UGreen, Philips and HP. The experiments were conducted without modifying the target devices and without requiring physical access to them.
These results apply to the individual products and test conditions studied. They are not evidence that every device made by those manufacturers has the same weakness. Electronic designs can differ between models, versions and production runs.
For the headphone tests, the recovered information was the audio being played to the wearer. That could matter if someone were listening to a confidential customer call, a recorded meeting, a legal briefing or another source that people nearby could not normally hear.
Could the Attack Capture My Microphone Too?
The study also examined microphone signals, but the reported range was much shorter at approximately 30 centimetres.
This distinction is important. The headline 30-metre result related to audio being delivered through certain headphones with an external power amplifier. It should not be interpreted as proof that an attacker can capture every conversation taking place around a headset from the same distance.
Microphone leakage at 30 centimetres could still be relevant in a targeted setting, but it requires the attacker or equipment to be very close. The practical situation is different from receiving headphone playback across a room or from outside a nearby space.
Keeping those results separate avoids turning a specific research finding into a broader claim the study did not establish.
Can the Signal Travel Through a Wall?
The researchers conducted separate through-wall demonstrations. One example involved a distance of one metre through a 30-centimetre concrete wall.
They also recreated hotel and meeting-room situations to show why closing a door does not necessarily block electromagnetic leakage. A wall can stop ordinary sound from travelling clearly while still allowing some radio-frequency energy to pass.
That does not mean every wall, room or building provides the same result. Construction materials, reinforcement, other equipment and radio interference can all change what is detectable.
The demonstration is most relevant to higher-risk environments where a sensitive call takes place close to an adjoining room, corridor or publicly accessible area. Physical distance and controlled space still matter, but a closed door should not automatically be treated as complete protection against every technical listening method.
Why Encryption Does Not Prevent This Headphone Attack
Encryption protects information while it is stored or travelling between systems. A secure calling app can stop an unauthorised person from reading the network traffic between participants.
The headphones eventually need to turn that protected digital information into an electrical audio signal and then into sound. InjectEave targets unintended leakage from that later part of the process, after the content has already become usable audio.
The researchers describe the leakage as coming from the analogue path. This means the vulnerability sits in the physical circuitry handling the audio signal rather than in the encrypted wireless or internet connection.
Encryption remains essential. It protects against many more common forms of interception and should not be disabled because it cannot solve every hardware problem. The lesson is that confidential communication depends on the whole chain, including the software, network, computer, cables, headphones and physical surroundings.
Could Other Electronics Leak Information?
The research extended beyond speech and headphones. Tests involving smart fans and lamps showed that emissions could reveal operating speed or brightness levels.
Those measurements might support inferences about routines or device use, although they do not directly prove what a person is doing. A fan changing speed or a light changing brightness provides information about the device, not a complete account of activity in the room.
A separate landline demonstration combined recovered conversation audio with synthesised speech injected into the telephone's output. This suggests the technique could potentially support deception as well as surveillance in a carefully prepared attack.
These remain research demonstrations. The published findings do not establish that criminals are already using InjectEave against businesses or members of the public.
Should I Stop Using Headphones for Private Calls?
For most people and routine conversations, the study does not justify abandoning headphones. The attack requires specialist equipment and technical knowledge, and the 30-metre result depended on additional amplification and particular devices.
A proportionate response starts with the sensitivity of the information and the likelihood that someone would invest resources in obtaining it.
Everyday music, general meetings and ordinary personal calls are unlikely to justify the same controls as legal advice, merger discussions, defence work, sensitive research or conversations involving valuable intellectual property.
People handling highly confidential material should consider where calls take place, who can access nearby rooms and whether approved equipment has been selected for the environment. Moving a sensitive call away from an external wall or public corridor may be a simple precaution even when the technical risk is low.
What Businesses Should Learn From InjectEave
The study is a reminder that secure software does not remove every physical risk. Businesses often focus on passwords, encryption and account security while assuming that the device producing the final sound is private by default.
Start by identifying conversations where interception would cause serious harm. This may include executive decisions, legal discussions, security incidents, personal data, product plans and commercially sensitive customer information.
Consider the location as well as the calling platform. Hotels, shared offices, conference venues and meeting rooms beside public areas may deserve stronger precautions for the most sensitive work.
Organisations with demanding confidentiality requirements should ask equipment suppliers about electromagnetic compatibility, shielding and resistance to interference. Independent specialist advice may be appropriate in environments where technical surveillance is a realistic threat.
The researchers identify shielding, filtering and changes to internal wiring as possible ways to reduce exposure. They also warn that these measures raise the difficulty of an attack but do not guarantee immunity.
A normal software update should not be presented as a confirmed fix for a weakness in physical circuitry. Manufacturers may need hardware design changes, and the correct response will depend on the affected product.
A Practical Answer to the Headphone Privacy Question
Can someone listen to my headphones? In a carefully prepared attack against vulnerable equipment, the research shows that audio can be recovered from unintended electromagnetic emissions. The demonstrated distance was usually between one and six metres, with 30 metres achieved for two headphone models by adding an external radio-frequency power amplifier.
That is a meaningful security finding, but it is not evidence that strangers can routinely listen to any headphones from across the street. The attack requires dedicated equipment, suitable positioning and a target device that behaves in the necessary way.
For most organisations, the sensible response is not panic or immediate replacement of every headset. It is to match the protection to the sensitivity of the conversation, choose appropriate equipment and remember that privacy depends on both digital security and the physical devices at each end.
For businesses that need help protecting confidential communications, devices and working environments, our Cyber Security Services page explains how we can help.