When Good Becomes Evil: Exploring Crosstalk Attack Surfaces on Multi-Port USB Chargers

Tao Ni, Zehua Sun, Yongliang Chen, Yihe Zhou, Jiayimei Wang, Weitao Xu, Qingchuan Zhao, Cong Wang · IEEE Transactions on Mobile Computing · 2025

Multi-port chargers, designed to simultaneously charge multiple mobile devices such as smartphones, have gained significant popularity, with millions of units sold in recent years. However, this multi-device charging feature introduces security and privacy risks. If not properly designed and implemented, these chargers can enable communication between connected devices because they are inherently interconnected, which leads to crosstalk voltage leakages. Despite their widespread use, these risks have not been thoroughly investigated. We have identified novel attack surfaces in the circuit design of multi-port chargers that allow an adversary who shares the multi-port charger with the target victim in close proximity to exploit one port to (i) recognize fine-grained user activities of other devices being charged, (ii) eavesdrop on secret audio transmission from USB-C audio pins, and (iii) inject malicious audio commands into built-in voice assistants of charging devices (e.g., Siri, Google Assistant). In this paper, we design and implement XPORTHEFT, a novel system to analyze and demonstrate the uncovered security and privacy threats in multi-port chargers. Specifically, it leverages changes in voltage signals in one neighbor port to monitor voltage changes in the charging port induced by user activities in various user interfaces, such as recognizing running apps and detecting keystrokes. Moreover, XPORTHEFT can also achieve audio transmission eavesdropping and launch inaudible audio injection attacks from the neighbor port to the charging mobile device via the USB-C interface. We extensively evaluate the effectiveness of XPORTHEFT using five commercial multi-port chargers and five mobile devices. The evaluation results show its high effectiveness in recognizing the launch of 20 mobile apps (88.7%) and revealing unlocking passcodes (98.8%), as well as eavesdropping on the audios of numeric digits (97.1%) and alphabetic characters (98.0%). Furthermore, XPORTHEFT achieves 100% success rates in inaudible audio injection attacks on three commercial voice assistants. In addition, our study also shows that XPORTHEFT is resilient to various impact factors and presents the potential to attack multiple victims.

Read the paper · More papers on PaperTik