Crossposted my comment from the crosspost:
They are basically introducing a carrier frequency that matches a frequency the device uses. By matching those, they are able to usr the devices own harmonics to amplify and return the signal.
They show that this can be done without any effects on the hardware, no trace. And can be done through 30cm solid concrete walls at a distance.
The tests, on wired and wireless audio devices return 100% usable and intelligible information in nearly every case and every situation.
The only situation they didn't seem to test was a victim using multiple identical devices. \
Eg. I'm a known target so i have 3 sets of headphones. 2 constantly playing random audio and 1 being the one carrying secrets.
Would they be able to differentiate between devices or would it all come back garbled? One test was transferability - the same model of device had the same vulnerable frequencies. If they 'injected' in a room full of the same devices, could they determine a single device?