AndroidPure
  • Leaks
  • News
  • Reviews
  • Updates
  • How to
No Result
View All Result
  • Leaks
  • News
  • Reviews
  • Updates
  • How to
No Result
View All Result
AndroidPure
No Result
View All Result

Android Ad SDKs Secretly Harvest Your Location Data, EFF Finds

Androidpure Staff by Androidpure Staff
August 5, 2026
in News

Four widely used advertising SDKs embedded in Android apps are quietly harvesting users’ precise location data by default, even when the app developer never intended to share it, according to a new investigation published by the Electronic Frontier Foundation on August 4.

The EFF examined InMobi, BidMachine, Verve’s HyBid, and Huawei’s Petal Ads SDK, and found that all four collect and forward a user’s location the moment the host app has location permission — with no separate SDK-level toggle for developers or users to restrict. Together, these four SDKs claim to reach billions of users across tens of thousands of apps. InMobi alone says it reaches more than two billion users in over 150 countries; Verve claims 1.5 billion users across 10,000-plus apps; and Huawei’s Petal Ads SDK is embedded in more than 85,000 apps worldwide.

How Android Location Data Leaks Through Ad SDKs

The core problem is a gap in Android’s permission model. When a user grants an app access to their location — say, for a weather forecast or a running route — every third-party SDK bundled inside that app inherits the same permission automatically. Android offers no SDK-specific location control. The EFF’s own documentation review confirmed that InMobi’s SDK “automatically forwards location signals when available,” and Verve’s documentation tells developers that “if the user has given location permissions, HyBid SDK will use the available user location to provide better targeted ads.”

The financial incentive compounds the design flaw. InMobi’s own developer documentation notes that “location-enriched impressions typically yield higher revenue,” giving both developers and SDK providers a reason to leave collection switched on.

To verify the real-world impact, EFF researchers Lena Cohen and Bill Budington analyzed network traffic from apps and identified two — QR Scanner (50 million+ downloads) and GPS Speedometer (10 million+ downloads) — actively sending precise user coordinates to BidMachine’s servers.

Where the Data Ends Up

The harvested location histories flow from SDKs to data brokers who resell them to advertisers, and in documented cases, to governments and intelligence agencies. As Budington put it in the EFF’s press release:

“When developers let advertising SDKs collect location data, they’re putting users at risk of more than just creepy ads. Location information sourced from the advertising industry has been used for ICE investigations, global spy tools, outing a gay priest, tracking union organizers, and tracking US military personnel.”

The EFF’s report is blunt about the consent gap: “App-level location permissions alone cannot signal meaningful consent to location collection and sharing by third-party advertising SDKs.” A second passage adds: “Advertising SDKs should not make sharing personal data the default, especially for data as sensitive as a person’s location.”

What Users and Developers Can Do

For Android users, the most direct mitigation is reviewing which apps have location access. Go to Settings > Location > App location permissions and switch any app that doesn’t genuinely need your location to “Don’t allow.” Apps that need location only while in use — like navigation — should be set to “Allow only while using the app” rather than “Allow all the time.” This won’t block SDK-level collection within a permitted app, but it shrinks the surface area significantly.

For developers, the EFF urges disabling unnecessary location data collection in every advertising SDK configuration and auditing SDK documentation for default-on collection settings. The organization also calls on US legislators to enact federal location privacy protections, since Android’s own permission architecture cannot currently distinguish between an app’s legitimate location use and an embedded SDK’s commercial harvesting of the same data.

The EFF notes that the four SDKs examined are a small sample — other advertising SDKs not covered in the report have also faced criticism and lawsuits for similar location data practices.

Source: EFF

Tags: advertising sdkAndroidefflocation dataPrivacy
ShareTweetSendShare
Previous Post

Pixel Watch 5 Leak Reveals Full Specs and a Price Hike Across All Models

Next Post

Pixel 7a Misses a Monthly Update for the First Time as Google Quietly Abandons Cadence

Androidpure Staff

Androidpure Staff

Androidpure Staff delivers the latest from the Android world — phone launches, software updates, and practical how-to guides — without the press-release fluff. We focus on what genuinely matters to readers, in India and around the globe.

Follow Us

  • 914 Followers

Popular

  • OnePlus N6x in Burgundy Red, front view and side profile from OnePlus India's official launch render

    OnePlus N6x Launched in India at Rs 18,999: Price, Specs, Sale Date

    Share
    Share Tweet
  • OriginOS 7 Beta Opens: The Five vivo and iQOO Devices Eligible First

    Share
    Share Tweet
  • JioTag 2 Launches in India at Rs 1,249 With Find Hub and Find My

    Share
    Share Tweet
  • POCO M8 Power 5G Launched in India: Price Starts at Rs 24,999 With 8,000mAh Battery

    Share
    Share Tweet
  • Redmi K100 Pro Max Shows Up With a 9,070mAh Battery Before Launch

    Share
    Share Tweet
  • Coolpad Mega 2.5D Review : Great build, Front shooter yet low on performance

    Share
    Share Tweet
  • Galaxy F70 Pro 5G Lands in India August 3, Samsung Confirms Specs

    Share
    Share Tweet

Latest

Google logo, Pixel 6 and Pixel 7 August 2026 update skipped

Pixel 7a Misses a Monthly Update for the First Time as Google Quietly Abandons Cadence

August 5, 2026
Electronic Frontier Foundation logo

Android Ad SDKs Secretly Harvest Your Location Data, EFF Finds

August 5, 2026
Google logo representing Pixel Watch 5 leak ahead of August 12 event

Pixel Watch 5 Leak Reveals Full Specs and a Price Hike Across All Models

August 5, 2026
Samsung logo representing Galaxy XCover 6 Pro security update policy change

Galaxy XCover 6 Pro Loses Monthly Security Updates: Samsung Moves It to Quarterly

August 5, 2026
Redmi K100 Pro in Firefly Chasing Light green colorway with glow-in-the-dark rear panel

Redmi K100 Pro Runs a Cut-Down Snapdragon 8 Elite Gen 5 V Series: Here’s What That Means

August 4, 2026
Apple logo, the company fighting UK government encryption backdoor demands

Apple’s UK Encryption Fight Could Set a Precedent for Android Backup Privacy

August 4, 2026
OPPO A7 Pro Max 5G official product image

OPPO A7 Pro Max China Price Confirmed: Starts at CNY 2,199 With 10,000mAh Battery

August 4, 2026
AndroidPure

© 2024 AndroidPure - NonStop Android.

Navigate Site

  • Privacy
  • About Us
  • Tip Us
  • Contact Us

Follow Us

No Result
View All Result
  • Leaks
  • News
  • Reviews
  • Updates
  • How to

© 2024 AndroidPure - NonStop Android.