Android3 mins read

Android apps may be quietly sharing users’ location data with advertisers

TechCrunch reports that Electronic Frontier Foundation findings warn Android developers that third-party SDKs in their apps may collect precise user location data by default when an app has location permission.

The core risk: SDKs can inherit app permissions

TechCrunch reports that new Electronic Frontier Foundation findings warn Android developers about third-party code embedded in their apps. When a user grants an app permission to access precise location, some software development kits, or SDKs, may inherit that permission and collect the same location data. The concern is that developers may not know this data-sharing setting is enabled by default.

Why this matters for developers

Location access can be legitimate for apps like weather or fitness tools, but the EFF’s warning focuses on collection that may happen beyond the app’s core function. The group urged app makers to disable unnecessary data collection whenever possible. For developers, the takeaway is direct: review third-party SDK settings, especially defaults tied to sensitive permissions.

Where the data can go

Advertising SDKs are promoted as a way for developers to monetize apps, but TechCrunch reports that the trade-off can include users’ location histories being fed to data brokers. The article notes that this information can be monetized and sold to militaries, governments, and intelligence agencies, and that it creates security and privacy risks if hacked or stolen. The EFF also found that some Android apps quietly sharing location data included two apps downloaded a combined 60 million times.

Consent problem: app-level permission is not enough

The EFF ran tests by analyzing app network traffic to see which services received user location data. Its report said there are “no SDK-specific location permissions,” meaning a user’s approval for the app can also enable sharing with advertisers. The EFF wrote that “App-level location permissions alone cannot signal meaningful consent to location collection and sharing by third-party advertising SDKs.”

Discover More

    Cybersecurity-themed illustration used for a report on AI-generated exploit scripts targeting industrial control systems
    AI speeds ICS attacks

    U.S. agencies warn AI-generated exploit scripts are raising risks for exposed Siemens S7 industrial controllers.

    CybersecurityIndustrial Control Systems
    A T-Mobile store in Times Square with bright pink T-Mobile signage.
    T-Mobile Cut Off Hackers

    T-Mobile reportedly stopped Salt Typhoon activity by physically severing a compromised system’s connection.

    CybersecurityT-Mobile