EFF Flags 4 Android Ad SDKs Sharing Location by Default Across 85,000-Plus Apps
Updated
Updated · EFF · Aug 4
EFF Flags 4 Android Ad SDKs Sharing Location by Default Across 85,000-Plus Apps
3 articles · Updated · EFF · Aug 4
Summary
Four Android ad SDKs — InMobi, BidMachine, Verve’s HyBid and Huawei’s Petal Ads — were found by EFF to collect or pass location data by default once an app has location permission.
EFF said the leakage stems from SDK defaults, revenue incentives and murky documentation, with real-time bidding systems then exposing location data to advertisers and brokers without separate SDK-specific consent.
BidMachine changed documentation after EFF’s inquiry, while EFF said traffic from QR Scanner and GPS Speedometer showed precise coordinates sent to a BidMachine domain despite earlier claims that precise location was not collected.
The report says the four SDKs reach billions of users and are embedded in thousands of apps, underscoring how app-level permissions can quietly enable third-party tracking far beyond an app’s core function.
EFF urged developers to disable unnecessary collection and called for tougher regulatory scrutiny and federal location-privacy rules, arguing sensitive location sharing should never be the default.