Four widely used advertising SDKs embedded in Android apps are quietly harvesting users’ precise location data by default, even when the app developer never intended to share it, according to a new investigation published by the Electronic Frontier Foundation on August 4.
The EFF examined InMobi, BidMachine, Verve’s HyBid, and Huawei’s Petal Ads SDK, and found that all four collect and forward a user’s location the moment the host app has location permission — with no separate SDK-level toggle for developers or users to restrict. Together, these four SDKs claim to reach billions of users across tens of thousands of apps. InMobi alone says it reaches more than two billion users in over 150 countries; Verve claims 1.5 billion users across 10,000-plus apps; and Huawei’s Petal Ads SDK is embedded in more than 85,000 apps worldwide.
How Android Location Data Leaks Through Ad SDKs
The core problem is a gap in Android’s permission model. When a user grants an app access to their location — say, for a weather forecast or a running route — every third-party SDK bundled inside that app inherits the same permission automatically. Android offers no SDK-specific location control. The EFF’s own documentation review confirmed that InMobi’s SDK “automatically forwards location signals when available,” and Verve’s documentation tells developers that “if the user has given location permissions, HyBid SDK will use the available user location to provide better targeted ads.”
The financial incentive compounds the design flaw. InMobi’s own developer documentation notes that “location-enriched impressions typically yield higher revenue,” giving both developers and SDK providers a reason to leave collection switched on.
To verify the real-world impact, EFF researchers Lena Cohen and Bill Budington analyzed network traffic from apps and identified two — QR Scanner (50 million+ downloads) and GPS Speedometer (10 million+ downloads) — actively sending precise user coordinates to BidMachine’s servers.
Where the Data Ends Up
The harvested location histories flow from SDKs to data brokers who resell them to advertisers, and in documented cases, to governments and intelligence agencies. As Budington put it in the EFF’s press release:
“When developers let advertising SDKs collect location data, they’re putting users at risk of more than just creepy ads. Location information sourced from the advertising industry has been used for ICE investigations, global spy tools, outing a gay priest, tracking union organizers, and tracking US military personnel.”
The EFF’s report is blunt about the consent gap: “App-level location permissions alone cannot signal meaningful consent to location collection and sharing by third-party advertising SDKs.” A second passage adds: “Advertising SDKs should not make sharing personal data the default, especially for data as sensitive as a person’s location.”
What Users and Developers Can Do
For Android users, the most direct mitigation is reviewing which apps have location access. Go to Settings > Location > App location permissions and switch any app that doesn’t genuinely need your location to “Don’t allow.” Apps that need location only while in use — like navigation — should be set to “Allow only while using the app” rather than “Allow all the time.” This won’t block SDK-level collection within a permitted app, but it shrinks the surface area significantly.
For developers, the EFF urges disabling unnecessary location data collection in every advertising SDK configuration and auditing SDK documentation for default-on collection settings. The organization also calls on US legislators to enact federal location privacy protections, since Android’s own permission architecture cannot currently distinguish between an app’s legitimate location use and an embedded SDK’s commercial harvesting of the same data.
The EFF notes that the four SDKs examined are a small sample — other advertising SDKs not covered in the report have also faced criticism and lawsuits for similar location data practices.
Source: EFF





