Overview
- The EFF published a report that exposed advertising software development kits (SDKs) that, by default, collect and forward users’ precise location when an app has location permission.
- The investigation, which was published Tuesday, August 4, 2026, named four SDKs — InMobi, BidMachine, Verve’s HyBid, and Huawei’s Petal Ads — as examples that share location by default.
- Researchers reached their conclusions by reviewing public SDK developer documentation and by testing app network traffic to see which third parties receive location data.
- EFF flagged concrete risks after finding some widely installed Android apps sending location to ad systems, including two apps with a combined roughly 60 million downloads, and urged users to revoke app location permissions as an immediate fix.
- The report warns that location pipelines feed data brokers and advertisers that have been used by law enforcement and other actors, and it calls for developers to change SDK defaults, for Google to add finer-grained SDK controls, and for regulators to tighten oversight.