Skip to content

QIF-T0072

high

Transducer inversion (acoustic eavesdropping via speaker-to-microphone reprogramming)

Tier 2 — Validated (Independently Replicated)

Legacy status: CONFIRMED

Consumer audio hardware (earbuds, headphones, speakers) uses electromagnetic transducers that are physically bidirectional — a speaker cone can capture sound pressure waves just as a microphone diaphragm does. RealTek HD Audio codecs (used in most consumer PCs and many embedded devices) expose jack retasking registers that allow software to reassign an output jack as an input. The SPEAKE(a)R attack (Ben-Gurion University, 2017) demonstrated recording intelligible audio through headphones connected to an output-only jack by reprogramming the codec. In a supply chain attack scenario, generic earbuds (which lack proprietary protocol protections like Apple's W1/H1 chip authentication) could be modified at the factory or distribution level to include firmware that silently enables input mode, turning every pair of compromised earbuds into an ambient microphone. The captured audio is routed through the normal audio data path, making detection difficult. This is a pre-BCI eavesdropping vector: before any neural signal is involved, the attacker has ambient audio from the user's environment.

Technique Details

Tactic
QIF-S.RP
Status
CONFIRMED
Bands
S1, S2, S3

Therapeutic Application

Electromagnetic transducer bidirectionality exploited via codec register retasking to convert audio output hardware into covert microphone

Neural Impact

3 of 7 neural bands affected

S1 S2 S3

Drag to rotate. Click a region to learn more.

Click or hover over a glowing region to see the attack techniques targeting it and their severity.

Scoring

NISS v1.1 NISS:1.1/BI:N/CR:N/CD:N/CV:I/RV:F/NP:N
CVSS v4.0 CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
2.0Low
BICRCDCVRVNP
 

Governance

Neurorights at Risk

This technique threatens 1 of the 4 proposed neurorights (Ienca & Andorno, 2017).

Consent Complexity
0.12 / 4.0

FDORA §3305 Compliance

Cyber Device
Regulatory Coverage
0.5 / 1.0
524B Requirements
TM VA SBOM SA PM
Regulatory Gaps
  • ! No FDA pathway for consumer sensor exploitation
  • ! Software-only attack without software lifecycle standard (IEC 62304)

Population Vulnerability

CRB vulnerability adjustment (γ=0.30) accounts for age, diagnosis severity, consent capacity, and device dependency.

Population NISS Base Adjusted Severity Delta
Adult (Default) 2.0 2.0 Low -
Child (10yr) + ADHD 2.0 2.4 Low +0.35
Adult with ALS 2.0 2.3 Low +0.32

Validation Status

Theoretical / Not yet validated. This technique has not been independently tested. See the validation dashboard for what has been tested.

Qinnovate Neural Security Atlas Edit this on GitHub