Particle.news

EFF Says Some Android Ad SDKs Send Precise User Location to Advertisers by Default

The investigation finds third‑party ad code inherits an app’s location permission and shares exact coordinates with advertisers and data brokers without separate user consent.

Overview

  • The Electronic Frontier Foundation examined SDK docs and app network traffic and reported that some advertising SDKs collect and forward precise location data when an Android app has location permission.
  • The technical cause is permission inheritance: Android grants location to an app and many SDKs automatically use that permission because there is no per‑SDK consent control in the platform.
  • EFF highlighted four SDKsInMobi, BidMachine, Verve’s HyBid, and Huawei’s Petal Ads—as collecting location by default and found examples of affected apps including two with about 60 million combined downloads.
  • Users can stop apps from sharing location by changing App location permissions or turning off device location in Android settings, and EFF urged developers to disable SDK location collection when it is not needed.
  • No platform‑level fixes or regulatory actions have been reported so far, and the report warns that location flows into broker networks that have been used by governments, advertisers, and other parties in ways that can harm privacy and safety.