Briev
Live
Technology
UNDERREPORTED

Android SDKs may be passing users' precise location to advertisers by default

The Electronic Frontier Foundation found that many Android apps unintentionally share users' exact location with advertising SDKs, which then forward the data to third-party brokers.

A new study by the Electronic Frontier Foundation reveals that a number of Android applications are inadvertently leaking users' precise location data to third-party advertising SDKs. When a user grants an app permission to access location, the embedded SDK automatically inherits that permission and forwards the data to data brokers unless developers explicitly turn off the collection. The EFF highlights that such brokers may sell the information to militaries, governments and agencies like the FBI, and that past breaches have exposed similar data.

Network-traffic analysis identified two popular apps, together downloaded about 60 million times, that were quietly sharing location details. Bill Budington, a senior staff technologist at the EFF, noted that while the examined SDKs represent a small slice of the ad ecosystem, they still reach billions of users across tens of thousands of apps. The organization urges developers to disable unnecessary location collection and to treat location data as highly sensitive.

Why it matters

Unintended location sharing can compromise privacy and security for millions of Android users.

In this story

android appslocation dataadvertising SDKsdata brokersprivacy riskuser consentEFF study