Overview
- The Electronic Frontier Foundation examined SDK docs and app network traffic and reported that some advertising SDKs collect and forward precise location data when an Android app has location permission.
- The technical cause is permission inheritance: Android grants location to an app and many SDKs automatically use that permission because there is no per‑SDK consent control in the platform.
- EFF highlighted four SDKs—InMobi, BidMachine, Verve’s HyBid, and Huawei’s Petal Ads—as collecting location by default and found examples of affected apps including two with about 60 million combined downloads.
- Users can stop apps from sharing location by changing App location permissions or turning off device location in Android settings, and EFF urged developers to disable SDK location collection when it is not needed.
- No platform‑level fixes or regulatory actions have been reported so far, and the report warns that location flows into broker networks that have been used by governments, advertisers, and other parties in ways that can harm privacy and safety.