Particle.news

EFF Finds Some Mobile Ad SDKs Default to Sharing Users’ Precise Location

Default SDK settings funnel app-granted location permissions into brokered tracking networks, risking surveillance plus other harms.

Overview

  • The Electronic Frontier Foundation reviewed public developer documentation and app network traffic and found some advertising software development kits can collect and forward precise device location whenever an app has location permission.
  • EFF identified four SDKs that share location by default: InMobi, BidMachine, Verve’s HyBid, and Huawei’s Petal Ads.
  • The report shows three technical and commercial drivers of these flows: privacy-invasive default settings, opaque developer documentation, and ad monetization incentives that reward more granular location signals.
  • EFF tied advertising-sourced location feeds to documented harms, including use by immigration enforcement, tools linked to global spying, the outing of vulnerable people, and tracking of organizers and military personnel.
  • EFF urged developers to audit and disable unnecessary SDK location settings and called on regulators to close legal gaps, and the organization says the named SDK providers had not issued immediate public responses.