We propose a new class of signal injection attacks on microphones by\nphysically converting light to sound. We show how an attacker can inject\narbitrary audio signals to a target microphone by aiming an amplitude-modulated\nlight at the microphone's aperture. We then proceed to show how this effect\nleads to a remote voice-command injection attack on voice-controllable systems.\nExamining various products that use Amazon's Alexa, Apple's Siri, Facebook's\nPortal, and Google Assistant, we show how to use light to obtain control over\nthese devices at distances up to 110 meters and from two separate buildings.\nNext, we show that user authentication on these devices is often lacking,\nallowing the attacker to use light-injected voice commands to unlock the\ntarget's smartlock-protected front doors, open garage doors, shop on e-commerce\nwebsites at the target's expense, or even unlock and start various vehicles\nconnected to the target's Google account (e.g., Tesla and Ford). Finally, we\nconclude with possible software and hardware defenses against our attacks.\n