https://www.securityweek.com/earspy-spying-phone-calls-ear-speaker-vibrations-captured-accelerometer SECURITYWEEK NETWORK: * Cybersecurity News * Webcasts * Virtual Events Security Experts: WRITE FOR US Cybersecurity News, Insights and Analysis | SecurityWeek * Subscribe * 2022 CISO Forum * ICS Cyber Security Conference * Contact * Malware & Threats + Vulnerabilities + Email Security + Virus & Malware + IoT Security + Threat Intelligence + Endpoint Security * Cybercrime + Cyberwarfare + Fraud & Identity Theft + Phishing + Malware + Tracking & Law Enforcement * Mobile & Wireless + Mobile Security + Wireless Security * Risk & Compliance + Risk Management + Compliance + Privacy + Supply Chain * Security Architecture + Cloud Security + Identity & Access + Data Protection + Network Security + Application Security * Security Strategy + Risk Management + Security Architecture + Disaster Recovery + Training & Certification + Incident Response * ICS/OT * IoT Security Home > Mobile Security [picture-] EarSpy: Spying on Phone Calls via Ear Speaker Vibrations Captured by Accelerometer By Eduard Kovacs on December 28, 2022 Tweet [RSS-Icon] As smartphone manufacturers are improving the ear speakers in their devices, it can become easier for malicious actors to leverage a particular side-channel for eavesdropping on a targeted user's conversations, according to a team of researchers from several universities in the United States. The attack method, named EarSpy, is described in a paper published just before Christmas by researchers from Texas A&M University, Temple University, New Jersey Institute of Technology, Rutgers University, and the University of Dayton. EarSpy relies on the phone's ear speaker -- the speaker at the top of the device that is used when the phone is held to the ear -- and the device's built-in accelerometer for capturing the tiny vibrations generated by the speaker. Previous research focused on vibrations generated by a phone's loudspeakers, or it involved an external component for capturing data. However, an individual is more likely to use the ear speaker rather than the loudspeaker when receiving sensitive information in a phone call. The obvious choice for eavesdropping on a conversation would be for an attacker to plant a piece of malware that can record calls through the phone's microphone. However, Android security has improved significantly and it has become increasingly difficult for malware to obtain the required permissions. On the other hand, accessing raw data from the motion sensors in a smartphone does not require any special permissions. Android developers have started placing some restrictions on sensor data collection, but the EarSpy attack is still possible, the researchers said. A piece of malware planted on a device could use the EarSpy attack to capture potentially sensitive information and send it back to the attacker. EarSpy The researchers discovered that attacks such as EarSpy are becoming increasingly feasible due to the improvements made by smartphone manufacturers to ear speakers. They conducted tests on the OnePlus 7T and the OnePlus 9 smartphones -- both running Android -- and found that significantly more data can be captured by the accelerometer from the ear speaker due to the stereo speakers present in these newer models compared to the older model OnePlus phones, which did not have stereo speakers. The experiments conducted by the academic researchers analyzed the reverberation effect of ear speakers on the accelerometer by extracting time-frequency domain features and spectrograms. The analysis focused on gender recognition, speaker recognition, and speech recognition. In the gender recognition test, whose goal is to determine whether the target is male or female, the EarSpy attack had a 98% accuracy. The accuracy was nearly as high, at 92%, for detecting the speaker's identity. When it comes to actual speech, the accuracy was up to 56% for capturing digits spoken in a phone call. "[This] accuracy still exhibits five times greater accuracy than a random guess, which implies that vibration due to the ear speaker induced a reasonable amount of distinguishable impact on accelerometer data," the researchers said. Related: New Eavesdropping Technique Relies on Light Bulb Vibrations Related: New 'LidarPhone' Attack Uses Robot Vacuum Cleaners for Eavesdropping view counter Tweet [RSS-Icon] [picture-] Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia's security news reporter. Eduard holds a bachelor's degree in industrial informatics and a master's degree in computer techniques applied in electrical engineering. Previous Columns by Eduard Kovacs: CISA Says Two Old JasperReports Vulnerabilities Exploited in Attacks Several DoS, Code Execution Vulnerabilities Found in Rockwell Automation Controllers EarSpy: Spying on Phone Calls via Ear Speaker Vibrations Captured by Accelerometer Data of 400 Million Twitter Users for Sale as Irish Privacy Watchdog Announces Probe BetMGM Confirms Breach as Hackers Offer to Sell Data of 1.5 Million Customers CISO Forum: Invite-Only Community Engagement view counter 2023 ICS Cyber Security Conference | USA Oct. 23-26] view counter Advertise with SecurityWeek view counter Virtual Event Series - Security Summit Online Events by SecurityWeek view counter sponsored links #Tags: * Mobile Security * NEWS & INDUSTRY * Privacy * Mobile & Wireless * Privacy & Compliance View the discussion thread. [ ] [Search] Get the Daily Briefing [security_n] [Business Email Address ] [Subscribe] SecurityWeek News on Twitter SecurityWeek on Facebook Join our Group on LinkedIn Subscribe via RSS * Most Recent * Most Read * CISA Says Two Old JasperReports Vulnerabilities Exploited in Attacks * The Five Stories That Shaped Cybersecurity in 2022 * Several DoS, Code Execution Vulnerabilities Found in Rockwell Automation Controllers * Data Breach at Louisiana Healthcare Provider Impacts 270,000 Patients * Netwrix Acquires Remediant for PAM Technology * EarSpy: Spying on Phone Calls via Ear Speaker Vibrations Captured by Accelerometer * North Korean Hackers Created 70 Fake Bank, Venture Capital Firm Domains * Data of 400 Million Twitter Users for Sale as Irish Privacy Watchdog Announces Probe * Critical Vulnerability in Premium Gift Cards WordPress Plugin Exploited in Attacks * Microsoft Patches Azure Cross-Tenant Data Access Flaw Looking for Malware in All the Wrong Places? First Step For The Internet's next 25 years: Adding Security to the DNS Tattle Tale: What Your Computer Says About You Be in a Position to Act Through Cyber Situational Awareness Report Shows Heavily Regulated Industries Letting Social Networking Apps Run Rampant 2010, A Great Year To Be a Scammer. Don't Let DNS be Your Single Point of Failure How to Identify Malware in a Blink Defining and Debating Cyber Warfare The Five A's that Make Cybercrime so Attractive How to Defend Against DDoS Attacks Security Budgets Not in Line with Threats Anycast - Three Reasons Why Your DNS Network Should Use It The Evolution of the Extended Enterprise: Security Strategies for Forward Thinking Organizations Using DNS Across the Extended Enterprise: It's Risky Business Popular Topics * Cybersecurity News * IT Security News * Risk Management * Cybercrime * Cloud Security * Application Security * Smart Device Security Security Community * Virtual Cybersecurity Events * Webcast Library * CISO Forum * ICS Cyber Security Conference * IT Security Newsletters Stay Intouch * Twitter * Facebook * LinkedIn Group * Cyber Weapon Discussion Group * RSS Feed * Submit Tip * Security Intelligence Group About SecurityWeek * Team * Advertising * Event Sponsorships * Writing Opportunities * Feedback * Contact Us Wired Business Media Copyright (c) 2022 Wired Business Media. All Rights Reserved. Privacy Policy