AndroidPure
  • Leaks
  • News
  • Reviews
  • Updates
  • How to
No Result
View All Result
  • Leaks
  • News
  • Reviews
  • Updates
  • How to
No Result
View All Result
AndroidPure
No Result
View All Result

Android Ad SDKs Secretly Harvest Your Location Data, EFF Finds

Androidpure Staff by Androidpure Staff
August 5, 2026
in News

Four widely used advertising SDKs embedded in Android apps are quietly harvesting users’ precise location data by default, even when the app developer never intended to share it, according to a new investigation published by the Electronic Frontier Foundation on August 4.

The EFF examined InMobi, BidMachine, Verve’s HyBid, and Huawei’s Petal Ads SDK, and found that all four collect and forward a user’s location the moment the host app has location permission — with no separate SDK-level toggle for developers or users to restrict. Together, these four SDKs claim to reach billions of users across tens of thousands of apps. InMobi alone says it reaches more than two billion users in over 150 countries; Verve claims 1.5 billion users across 10,000-plus apps; and Huawei’s Petal Ads SDK is embedded in more than 85,000 apps worldwide.

How Android Location Data Leaks Through Ad SDKs

The core problem is a gap in Android’s permission model. When a user grants an app access to their location — say, for a weather forecast or a running route — every third-party SDK bundled inside that app inherits the same permission automatically. Android offers no SDK-specific location control. The EFF’s own documentation review confirmed that InMobi’s SDK “automatically forwards location signals when available,” and Verve’s documentation tells developers that “if the user has given location permissions, HyBid SDK will use the available user location to provide better targeted ads.”

The financial incentive compounds the design flaw. InMobi’s own developer documentation notes that “location-enriched impressions typically yield higher revenue,” giving both developers and SDK providers a reason to leave collection switched on.

To verify the real-world impact, EFF researchers Lena Cohen and Bill Budington analyzed network traffic from apps and identified two — QR Scanner (50 million+ downloads) and GPS Speedometer (10 million+ downloads) — actively sending precise user coordinates to BidMachine’s servers.

Where the Data Ends Up

The harvested location histories flow from SDKs to data brokers who resell them to advertisers, and in documented cases, to governments and intelligence agencies. As Budington put it in the EFF’s press release:

“When developers let advertising SDKs collect location data, they’re putting users at risk of more than just creepy ads. Location information sourced from the advertising industry has been used for ICE investigations, global spy tools, outing a gay priest, tracking union organizers, and tracking US military personnel.”

The EFF’s report is blunt about the consent gap: “App-level location permissions alone cannot signal meaningful consent to location collection and sharing by third-party advertising SDKs.” A second passage adds: “Advertising SDKs should not make sharing personal data the default, especially for data as sensitive as a person’s location.”

What Users and Developers Can Do

For Android users, the most direct mitigation is reviewing which apps have location access. Go to Settings > Location > App location permissions and switch any app that doesn’t genuinely need your location to “Don’t allow.” Apps that need location only while in use — like navigation — should be set to “Allow only while using the app” rather than “Allow all the time.” This won’t block SDK-level collection within a permitted app, but it shrinks the surface area significantly.

For developers, the EFF urges disabling unnecessary location data collection in every advertising SDK configuration and auditing SDK documentation for default-on collection settings. The organization also calls on US legislators to enact federal location privacy protections, since Android’s own permission architecture cannot currently distinguish between an app’s legitimate location use and an embedded SDK’s commercial harvesting of the same data.

The EFF notes that the four SDKs examined are a small sample — other advertising SDKs not covered in the report have also faced criticism and lawsuits for similar location data practices.

Source: EFF

Tags: advertising sdkAndroidefflocation dataPrivacy
TweetShareSendShare
Previous Post

Pixel Watch 5 Leak Reveals Full Specs and a Price Hike Across All Models

Next Post

Pixel 7a Misses a Monthly Update for the First Time as Google Quietly Abandons Cadence

Androidpure Staff

Androidpure Staff

Androidpure Staff delivers the latest from the Android world — phone launches, software updates, and practical how-to guides — without the press-release fluff. We focus on what genuinely matters to readers, in India and around the globe.

Follow Us

  • 914 Followers

Popular

  • Google G logo, the company's official brand mark

    Pixel 6 and 6 Pro: Google’s 5-Year Update Window Closes in October

    Share
    Share Tweet
  • iOS 27 Releases Monday, September 14: Apple’s Own Timing Confirmed

    Share
    Share Tweet
  • ColorOS 17 Stable Rollout Starts October 8: Full Device Schedule

    Share
    Share Tweet
  • Where Is the September Pixel Update? Android 17 QPR1 Still Pending

    Share
    Share Tweet
  • iPhone 18 Pro Max: US Model Missing Apple’s C2 Modem on Spec Sheet

    Share
    Share Tweet
  • iCloud+ Now Includes Apple TV and Apple Arcade in India

    Share
    Share Tweet
  • OnePlus 16 May Skip India, With the 16R Tipped as Flagship Instead

    Share
    Share Tweet

Latest

Google Gemini logo

Google Says Gemini Hacked Three Companies During a Security Test

September 19, 2026
Apple logo, maker of the iPhone 18 Pro

Apple Charges $129 to Replace an iPhone 18 Pro Battery, Up From $119

September 19, 2026
Vivo logo, maker of OriginOS 7 and iQOO phones

OriginOS 7 India Preview Closes Sept 20: Signup, Rollout Timeline

September 19, 2026
itel A300C in three color variants, showing the rear camera module and 6000mAh battery branding

itel A300C Launched in India at Rs. 10,999 With a 6,000mAh Battery

September 19, 2026
iPhone Duo shown folded and unfolded, held in two hands, illustrating the hinge and inner display discussed by Apple's VP of Hardware Engineering

Apple’s Hardware Chief Defends the iPhone Duo’s Crease and Warns Against Screen Protectors

September 19, 2026
Truecaller logo, the caller-ID app now required to share spam reports with Indian telecom operators under TRAI's amended rules

TRAI Now Requires Truecaller and Caller-ID Apps to Share Your Spam Reports With Telecom Operators

September 19, 2026
Lava Bold N4 Pro 5G in Monaco Blue and Opulent Lilac color options, rear camera module

Lava Bold N4 Pro 5G Launched in India at Rs 13,999

September 19, 2026
AndroidPure

© 2026 AndroidPure - NonStop Android.

Navigate Site

  • Privacy
  • About Us
  • Tip Us
  • Contact Us

Follow Us

No Result
View All Result
  • Leaks
  • News
  • Reviews
  • Updates
  • How to

© 2026 AndroidPure - NonStop Android.