QIF-T0072
highTransducer inversion (acoustic eavesdropping via speaker-to-microphone reprogramming)
Tier 2 — Validated (Independently Replicated)
Legacy status: CONFIRMED
Consumer audio hardware (earbuds, headphones, speakers) uses electromagnetic transducers that are physically bidirectional — a speaker cone can capture sound pressure waves just as a microphone diaphragm does. RealTek HD Audio codecs (used in most consumer PCs and many embedded devices) expose jack retasking registers that allow software to reassign an output jack as an input. The SPEAKE(a)R attack (Ben-Gurion University, 2017) demonstrated recording intelligible audio through headphones connected to an output-only jack by reprogramming the codec. In a supply chain attack scenario, generic earbuds (which lack proprietary protocol protections like Apple's W1/H1 chip authentication) could be modified at the factory or distribution level to include firmware that silently enables input mode, turning every pair of compromised earbuds into an ambient microphone. The captured audio is routed through the normal audio data path, making detection difficult. This is a pre-BCI eavesdropping vector: before any neural signal is involved, the attacker has ambient audio from the user's environment.
Technique Details
- Tactic
- QIF-S.RP
- Status
- CONFIRMED
- Bands
- S1, S2, S3
✚ Therapeutic Application
Electromagnetic transducer bidirectionality exploited via codec register retasking to convert audio output hardware into covert microphone
Neural Impact
3 of 7 neural bands affected
Drag to rotate. Click a region to learn more.
Click or hover over a glowing region to see the attack techniques targeting it and their severity.
Scoring
NISS:1.1/BI:N/CR:N/CD:N/CV:I/RV:F/NP:N CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N Governance
Neurorights at Risk
This technique threatens 1 of the 4 proposed neurorights (Ienca & Andorno, 2017).
FDORA §3305 Compliance
- ! No FDA pathway for consumer sensor exploitation
- ! Software-only attack without software lifecycle standard (IEC 62304)
Population Vulnerability
CRB vulnerability adjustment (γ=0.30) accounts for age, diagnosis severity, consent capacity, and device dependency.
| Population | NISS Base | Adjusted | Severity | Delta |
|---|---|---|---|---|
| Adult (Default) | 2.0 | 2.0 | Low | - |
| Child (10yr) + ADHD | 2.0 | 2.4 | Low | +0.35 |
| Adult with ALS | 2.0 | 2.3 | Low | +0.32 |
Validation Status
Theoretical / Not yet validated. This technique has not been independently tested. See the validation dashboard for what has been tested.