“Mic-E-Mouse” Attack Lets Hackers Steal Sensitive Data via Mouse Sensors
A cybersecurity vulnerability has been identified that allows for the transformation of standard computer mice into eavesdropping devices.
A cybersecurity vulnerability has been identified that allows for the transformation of standard computer mice into eavesdropping devices.
Researchers have developed the "Mic-E-Mouse" attack, which utilizes high-performance optical sensors in consumer mice to capture user conversations through acoustic vibrations transmitted via work surfaces.
This attack leverages the advanced optical sensors in modern computer mice, originally designed for precision tracking, to detect acoustic vibrations that occur when users speak. These vibrations are transmitted through desks and other work surfaces.
The initial captured signals suffer from poor quality due to non-uniform sampling and extreme quantization. However, researchers have created a processing pipeline utilizing signal processing and machine learning techniques to reconstruct intelligible speech.
A cybersecurity vulnerability has been identified that allows for the transformation of standard computer mice into eavesdropping devices.
Tests conducted on consumer-grade sensors using VCTK and AudioMNIST speech datasets have demonstrated an SI-SNR increase of +19dB, a speaker recognition accuracy of 80% in automated tests, and a word error rate of 16.79% in human studies. The pipeline captures human speech frequencies between 200Hz and 2000Hz, covering most conversational audio.
As high-performance mice become more accessible, this vulnerability poses a significant risk across consumer, corporate, and government environments. Devices with vulnerable sensors are available for under $50, increasing the potential reach of this attack vector.
The threat model targets applications that collect high-frequency mouse data, such as creative software and video games, which serve as ideal delivery vehicles for the exploit. These applications can include networking code that attackers might use to extract collected mouse data discreetly.
The Mic-E-Mouse pipeline can operate invisibly to users during data collection. Attackers require access to a vulnerable mouse and compromised software on the victim's computer, potentially using benign web-based applications. Data processing and analysis can occur offline, enhancing the stealth and feasibility of the attack.
This finding underscores a previously unknown attack vector that turns common computer peripherals into surveillance devices, raising privacy concerns for users of devices with advanced optical sensors.
Based on reporting by GBHackers.
