< Back to all clusters
[TECHNOLOGY] · 7 sources

started · updated

Android advertising SDKs collect user location data by default

An investigation by the Electronic Frontier Foundation (EFF) has revealed that several advertising Software Development Kits (SDKs) embedded in Android applications automatically collect and share user location data. This data harvesting occurs by default once a host application is granted location permissions, often without the explicit consent of the user or the knowledge of the app developer.

Key advertising platforms identified in the report include InMobi, BidMachine, Verve/HyBid, and Huawei Petal Ads. These SDKs are integrated deep within application code to facilitate measurement and ad optimization. Because Android currently lacks a mechanism to grant location permissions to individual SDKs separately from the host application, any SDK within the app inherits the permissions granted by the user.

The scale of the issue is significant, with the identified SDKs potentially reaching over 2 billion users through tens of thousands of applications. The collected data is often passed through real-time bidding pipelines to commercial data brokers, creating risks of unauthorized tracking and potential exposure of sensitive user movement histories.

Entities

Android · Android operating system · BidMachine · Electronic Frontier Foundation · Federal Bureau of Investigation · Huawei · InMobi · advertising SDKs

Claims

What the coverage asserts, and how many sources carry each claim.