Truth that Matters. Stories that Impact

Truth that Matters. Stories that Impact

Technology

Android App Developers May Unwittingly Share Precise Location Data With Advertisers, EFF Warns

Many Android app developers may unknowingly share their users’ precise location data with advertisers and data brokers due to default settings in third-party software development kits (SDKs). According to findings by the Electronic Frontier Foundation (EFF), when users grant location permissions to an app, included advertising SDKs automatically inherit those permissions and collect sensitive location records unless developers manually opt out.

What Happened

An investigation by the Electronic Frontier Foundation (EFF) revealed that third-party code snippets embedded in Android apps frequently collect location data by default. When a user grants location access to an app—such as a weather or fitness tracker—advertising SDKs integrated into the app inherit those exact same permissions. Because there are currently no SDK-specific location permissions within the operating system, the third-party code collects and transmits precise user location data to advertisers and data brokers without requiring separate consent.

EFF identified several Android apps engaging in this default location sharing, including two applications that have been downloaded over 60 million times combined. Researchers confirmed the behavior by analyzing network traffic to track where location data was being directed.

Key Highlights

  • Third-party advertising SDKs inherit an app’s location permissions and collect precise location data by default unless actively disabled by developers.
  • EFF’s testing involved analyzing network traffic from Android apps, identifying two affected apps with a combined 60 million downloads.
  • Android lacks SDK-specific location permissions, meaning app-level location consent automatically extends to embedded third-party ad libraries.
  • Data brokers collect and monetize user location histories, selling information to entities such as militaries, governments, and intelligence agencies like the FBI.
  • EFF senior staff technologist Bill Budington stated to TechCrunch that while the tested SDKs represent a small segment of the advertising market, they claim to reach billions of users across tens of thousands of apps.

Why This Matters

Advertising SDKs provide developers with a mechanism to monetize their applications. However, this model creates significant privacy and security risks. Once data brokers obtain user location histories, that sensitive data can be sold to third parties, including government agencies and intelligence organizations like the FBI. Additionally, stored location data poses severe security threats if data broker databases are hacked or stolen, an issue several data brokers have previously experienced.

What to Watch Next

The EFF has urged app developers to inspect their integrated code and disable unnecessary default data collection whenever possible. Privacy advocates emphasize that advertising SDKs should not make personal location sharing the default, calling for changes in how third-party permissions and user consent are handled in app ecosystems.

Frequently Asked Questions

Why do SDKs collect location data without separate permission?

Android currently lacks SDK-specific location permissions. When a user grants location access to an app, any embedded advertising SDK automatically inherits those permissions unless the developer manually turns off the data-sharing feature.

How did the EFF discover this location data sharing?

EFF researchers analyzed the network traffic of various Android apps to see which third-party services and servers were receiving users’ location details.

Who ultimately gets access to this location data?

Location details gathered by advertising SDKs are fed to data brokers. These brokers monetize the information by selling location histories to advertisers, government entities, militaries, and intelligence agencies like the FBI.

Source: Based on reporting from TechCrunch and research published by the Electronic Frontier Foundation (EFF).

Leave a Reply

Your email address will not be published. Required fields are marked *