An ultrasound frequency range too high for humans to hear is being used to hack smart device microphones and voice assistants such as Siri, Google Assistant, Alexa, and Cortana. Researchers at the University of Texas at San Antonio (UTSA) and University of Colorado Colorado Springs (UCCS) developed a Near-Ultrasound Inaudible Trojan (NUIT), which uses the frequency range to remotely access exploits vulnerabilities in the device microphones. Attacks can be achieved two ways: exploiting the speaker to attack a microphone on the same device (NUIT-1) or by exploiting the speaker on one device to attack a microphone on another device (NUIT-2).
MALICIOUS WEBSITES, APPS AND AUDIO Hackers lure unsuspecting victims to malicious websites, malicious apps, or malicious audio. Victims' devices become vulnerable after, e.g. watching a YouTube video embedded with NUIT audio, which can either use the device's microphone to attack the same device, or infiltrate the microphone via speakers from other devices. "If you play YouTube on your smart TV, that smart TV has a speaker. The sound of NUIT malicious commands will become inaudible, and it can attack your smart phone and communicate with your Google Assistant or Alexa. It can even happen in Zoom meetings. If someone unmutes themselves, they can embed the attack signal to hack your phone that's placed next to your computer during the meeting," explained Professor Guenevere Chen, an associate professor in the UTSA Department of Electrical and Computer Engineering and one of the researchers on the project.
Another scenario might be a malicious app playing the inaudible NUIT audio, telling a user's phone to set the audio to minimum, so the victim can't hear the voice assistant talk, and then the NUIT audio instructs the voice assistant to unlock the front door of the victim's house, all without the victim knowing.
FIXING THE ISSUE Out of the 17 smart devices the researchers tested, only Apple Siri needed the user's voice to operate, while other voice assistants could be activated by any voice, even a robot's. "This is not only a software issue or malware," said Chen. "It’s a hardware attack that uses the internet. The vulnerability is the non-linearity of the microphone design, which the manufacturer would need to address."
As a means of fixing the issue, its recommend users authenticate their voice assistants, be wary when clicking on links, grant microphone permissions, and use earphones instead of speakers.
“If you don’t use the speaker to broadcast sound, you’re less likely to get attacked by NUIT. Using earphones sets a limitation where the sound from earphones is too low to transmit to the microphone. If the microphone cannot receive the inaudible malicious command, the underlying voice assistant can’t be maliciously activated by NUIT,” Chen explained.
In the wake of the NUIT findings, CVE-2023-33248 was issued for "Amazon Alexa software version 8960323972 ... (which) potentially allows attackers to deliver security-relevant commands via an audio signal between 16 and 22 kHz".
Reference Links
https://sites.google.com/view/nuitattack/home
https://www.usenix.org/system/files/sec23fall-prepub-261-xia-qi.pdf




