Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

techcrunch+1techcrunch+1eff+1The Electronic Frontier Foundation has published new research revealing that Android app developers are inadvertently sharing millions of users' precise location data with advertisers and data brokers through embedded third-party software development kits, raising fresh concerns about the mobile advertising ecosystem's hidden data pipelines.
The EFF's report, published this week, found that advertising SDKs integrated into Android apps can inherit the host app's location permissions by default, collecting users' precise geolocation data without requiring separate consent. Unless developers actively disable the collection, these code libraries begin siphoning location information the moment a user grants the app access.techcrunch+2
"App-level location permissions alone cannot signal meaningful consent to location collection and sharing by third-party advertising SDKs," the EFF wrote in its report. "Advertising SDKs should not make sharing personal data the default, especially for data as sensitive as a person's precise location."mezha+2
Among the apps the EFF identified quietly sharing location data were two that had been downloaded a combined 60 million times, according to TechCrunch. The organization ran its tests by analyzing apps' network traffic to determine which services were receiving user location data.techcrunch+1
The research highlights a structural weakness in Google's Alphabet Inc. Android permission framework. While Android requires explicit user consent before an app can access location data, there are "no SDK-specific location permissions," the EFF noted. Once a user grants location access to an app, every third-party library embedded within it can tap that same data stream — creating what privacy advocates describe as a consent gap.mezha+1
The entities offering those SDKs are "generally commercially incentivized to get their customers to collect more data," TechCrunch reported. Location histories collected through these channels end up with data brokers who sell the information to advertisers, retailers, and government agencies including the FBI and military intelligence.techcrunch+1
The findings arrive amid a tightening regulatory landscape. Virginia became the third U.S. state to ban the sale of geolocation data in April 2026, and privacy frameworks including Europe's GDPR and California's CCPA classify location data among the most sensitive categories of personal information.techbuzz+1
The EFF urged developers to audit their SDK integrations and disable unnecessary data collection. Privacy advocates are pushing for new technical standards that would require SDKs to declare their data practices in machine-readable formats, enabling automated audits by app stores and developer tools. For now, the burden falls largely on developers — many of whom lack the resources to scrutinize the third-party code they depend on to monetize their apps.techcrunch+2