• Home
  • News
  • Fortune 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechCybersecurity

Inaudible Soundwaves Expose a Spooky New Pathway for Hackers

By
David Z. Morris
David Z. Morris
Down Arrow Button Icon
By
David Z. Morris
David Z. Morris
Down Arrow Button Icon
October 30, 2016, 1:47 PM ET

In a presentation scheduled for this week’s Black Hat conference in London, security researchers from University College London will outline how new marketing software that uses ultrasound signals could also expose millions of devices to malicious hacking.

The underlying technology in question is known as ultrasonic cross-device tracking, or uXDT. Cross-device tracking has been called a ‘holy grail’ for marketers, allowing them to, for instance, tell your phone when you’re watching a particular TV show, or share data about laptop web browsing to your tablet. A variety of startups and services, including Korea’s Soundlly and the rewards app Shopkick, are developing or using versions of the technology.

Get Data Sheet, Fortune’s technology newsletter.

There are already well-documented concerns about uXDT that have little to do with hackers. In March, the Federal Trade Commission warned several developers using software called Silverpush that they risked violating privacy guidelines by failing to disclose that apps could monitor user’s TV viewing habits.

The UCL team says the lack of disclosure and opt-out options on widely-installed uXDT apps represents an even bigger threat, though. Such apps often actively listen for ultrasound signals, even when the app itself is closed, creating a new and relatively poorly-understood pathway for hacking.

The researchers have already found ways to mine cloaked IP addresses. Speaking to New Scientist, UCL team member Vasilios Mavroudis suggests that an app’s always-on microphone access could be leveraged to monitor conversations (and, if you’re not paranoid already, to decipher what you’re typing). The ‘beacons’ that transmit ultrasound data can also be spoofed to manipulate apps’ user data.

For more on cybersecurity, watch our video.

This isn’t the first time that soundwaves have been implicated in hacking. In 2013, a security consultant named Dragos Ruiu said he witnessed several “air-gapped” machines—those with no Internet, Bluetooth, or other exploitable network connection—nonetheless spread an apparent virus strain he dubbed “badBIOS.” Ruiu initially speculated the persistent infection was being spread between machines via ultrasound. Though researchers have since largely debunked that theory, and though ultrasound can’t carry large amounts of data, something similar seems technically feasible.

The risk of ultrasound is particularly concerning because it’s a candidate for use in communication between the growing mass of Internet of Things devices. There are, according to Mavroudis, currently no standards for securing ultrasound beacons and signals. With last week’s massive IoT botnet attack still fresh in our memory, the UCL researchers are hoping to encourage the development of such standards. In the meantime, they’re also introducing a patch for Android that will allow better user supervision of ultrasound access.

About the Author
By David Z. Morris
See full bioRight Arrow Button Icon

Latest in Tech

Alex Karp smiles on stage
Big TechPalantir Technologies
Alex Karp credits his dyslexia for Palantir’s $415 billion success: ‘There is no playbook a dyslexic can master… therefore we learn to think freely’
By Lily Mae LazarusDecember 3, 2025
26 minutes ago
Isaacman
PoliticsNASA
Billionaire spacewalker pleads his case to lead NASA, again, in Senate hearing
By Marcia Dunn and The Associated PressDecember 3, 2025
37 minutes ago
Kris Mayes
LawArizona
Arizona becomes latest state to sue Temu over claims that its stealing customer data
By Sejal Govindarao and The Associated PressDecember 3, 2025
52 minutes ago
Startups & VentureLeadership Next
Only social media platforms with ‘real humanity’ will survive, investor and Reddit cofounder Alexis Ohanian says
By Fortune EditorsDecember 3, 2025
1 hour ago
NewslettersCIO Intelligence
Dave’s Hot Chicken is placing broad bets on AI to give the restaurant chain an edge in the chicken wars
By John KellDecember 3, 2025
2 hours ago
AITech
IBM CEO warns there’s ‘no way’ hyperscalers like Google and Amazon will be able to turn a profit at the rate of their data center spending
By Marco Quiroz-GutierrezDecember 3, 2025
2 hours ago

Most Popular

placeholder alt text
North America
Jeff Bezos and Lauren Sánchez Bezos commit $102.5 million to organizations combating homelessness across the U.S.: ‘This is just the beginning’
By Sydney LakeDecember 2, 2025
1 day ago
placeholder alt text
Economy
Ford workers told their CEO 'none of the young people want to work here.' So Jim Farley took a page out of the founder's playbook
By Sasha RogelbergNovember 28, 2025
5 days ago
placeholder alt text
North America
Anonymous $50 million donation helps cover the next 50 years of tuition for medical lab science students at University of Washington
By The Associated PressDecember 2, 2025
1 day ago
placeholder alt text
Economy
Elon Musk says he warned Trump against tariffs, which U.S. manufacturers blame for a turn to more offshoring and diminishing American factory jobs
By Sasha RogelbergDecember 2, 2025
1 day ago
placeholder alt text
Success
Warren Buffett used to give his family $10,000 each at Christmas—but when he saw how fast they were spending it, he started buying them shares instead
By Eleanor PringleDecember 2, 2025
1 day ago
placeholder alt text
C-Suite
MacKenzie Scott's $19 billion donations have turned philanthropy on its head—why her style of giving actually works
By Sydney LakeDecember 2, 2025
1 day ago
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.