Researchers Heard Headphone Audio From 30 Metres Away Without Hacking Bluetooth
Headphones are meant to keep a conversation from carrying across a room. A new research demonstration asks a different question: what if the electronics driving that private audio could be made to broadcast a faint copy of it? The InjectEave team reports recovering headphone audio from tested devices as far as 30 metres away, without compromising Bluetooth, Wi-Fi, a phone or the meeting software.
The work, posted on 4 September at 06:22 UTC, and presented through the researchers’ project site, is a laboratory proof of concept. That posting time was 08:22 in Madrid. It involves specialised but commercially available radio-frequency equipment near the target. The researchers tested 11 commercial devices. Their demonstrations included wired and wireless headphones, a landline phone and some smart-home devices. They do not report criminals using the technique in the wild or show that every pair of headphones can be read at 30 metres.
How headphone audio becomes a measurable signal
Electrical circuits can emit tiny electromagnetic signals as they operate. A spoken voice or headphone audio signal is relatively low-frequency, while a device’s wiring may radiate more efficiently at much higher radio frequencies. That mismatch normally makes the original sound difficult to recover by simply listening for emissions.
InjectEave changes the conditions. The researchers transmit a chosen radio-frequency carrier towards the device. Nonlinear components, such as amplifiers and converters, can mix that carrier with the audio signal. The device then unintentionally radiates a new signal carrying traces of the audio in a frequency range that is easier to receive. The team captures and processes the emission to reconstruct the sound. The attack is against an analogue physical path, not a flaw in a wireless networking protocol.
That is why disabling Bluetooth does not automatically answer the finding. The paper reports headphone audio leakage from both wired and wireless setups. Equally, it does not mean any stranger on the internet can switch on an eavesdropping function. The demonstration requires suitable proximity, radio equipment, a workable physical environment and the target hardware to be active. The team reached 30 metres under its experimental conditions. That is not a guaranteed range in every office or home.
The part that moves beyond passive listening
The research is notable because it actively induces a side channel rather than merely recording whatever a device leaks on its own. The team also describes a closed-loop landline-phone case study. It recovered call context, then injected synthesised audio towards the device in a controlled scenario. This demonstrates a possible integrity problem as well as a confidentiality problem, but it is still a research setup. It is not evidence that real calls have been manipulated this way.
For most people, ordinary account compromise, phishing and unwanted recordings remain more immediate risks. The InjectEave result is particularly relevant to rooms where spoken information is genuinely high-value: government, defence, legal, research and corporate discussions that already manage physical eavesdropping threats. A team cannot assess those spaces only by checking whether devices have current software patches. The audio path, cables, peripherals, room boundaries and nearby access may matter too.
What headphone audio leakage means for defenders
The researchers discuss hardware-aware measures such as shielding, filtering and twisted-pair wiring to reduce coupling between an injected signal and the device. They do not present a simple universal software patch or a consumer setting that makes tested hardware immune. Organisations with high-assurance rooms should review their physical and electromagnetic threat model with qualified specialists. They need not make ad hoc purchases based on one dramatic range figure.
Vendors should ask whether external radio-frequency energy can interact with the analogue path. Can the device then radiate information users expected to remain private? Vendors must measure the answer on actual hardware under realistic conditions. The project does not justify claiming that every device with a nonlinear component is practically exploitable, even though nonlinearity is widespread.
The most unsettling point is the trust boundary. Encrypted transport can protect audio up to a headset. The hardware can still emit a signal when it converts that audio for human ears. InjectEave does not make encryption useless. It shows where encryption ends and hardware and space take over. Our GPUThor analysis examines another physical hardware mechanism that can undermine a trusted mitigation.
Sources
- Yan, Shao, Zhang, Jiang and Long, Injected and Leaked, first posted 4 September 2026 at 06:22 UTC.
- InjectEave research project, method, equipment and demonstrations, consulted 14 September 2026.


