Updated
Updated · EFF · Aug 4
EFF Flags 4 Android Ad SDKs Sharing Location by Default Across 85,000-Plus Apps
Updated
Updated · EFF · Aug 4

EFF Flags 4 Android Ad SDKs Sharing Location by Default Across 85,000-Plus Apps

3 articles · Updated · EFF · Aug 4

Summary

  • Four Android ad SDKs — InMobi, BidMachine, Verve’s HyBid and Huawei’s Petal Ads — were found by EFF to collect or pass location data by default once an app has location permission.
  • EFF said the leakage stems from SDK defaults, revenue incentives and murky documentation, with real-time bidding systems then exposing location data to advertisers and brokers without separate SDK-specific consent.
  • BidMachine changed documentation after EFF’s inquiry, while EFF said traffic from QR Scanner and GPS Speedometer showed precise coordinates sent to a BidMachine domain despite earlier claims that precise location was not collected.
  • The report says the four SDKs reach billions of users and are embedded in thousands of apps, underscoring how app-level permissions can quietly enable third-party tracking far beyond an app’s core function.
  • EFF urged developers to disable unnecessary collection and called for tougher regulatory scrutiny and federal location-privacy rules, arguing sensitive location sharing should never be the default.

Insights

Are your favorite free Android apps secretly letting advertisers track your exact location without your knowledge?
Why do mobile operating systems still allow hidden third-party ad code to automatically inherit sensitive permissions?