Thursday, August 27, 2026
Tech Beat
Aug 4, 2026, 8:26 PMPrivacy & Security

EFF Warns Android Ad SDKs May Share Precise Location Data by Default

EFF warns Android ad SDKs can inherit app location permissions by default, quietly exposing precise user data to advertisers, brokers and agencies at scale.

Editorial illustration for EFF Warns Android Ad SDKs May Share Precise Location Data by Default

Summary

What happened, On August 4, 2026, TechCrunch reported Electronic Frontier Foundation findings that some Android applications may transmit precise location information to advertising companies and data brokers without their developers fully realizing it. The issue arises when developers add third-party software development kits, or SDKs, to generate advertising revenue. If an application has permission to use precise location, an embedded SDK can inherit that access unless the developer deliberately disables the SDK’s collection setting. The EFF argues that data sharing this sensitive should not be enabled by default.

Evidence and scale, The EFF examined applications’ network traffic to determine which outside services received location information. It identified Android apps that were quietly passing that data to third parties, including two apps with a combined 60 million downloads. Bill Budington, a senior staff technologist at the organization, said the SDKs examined represent only a small portion of the overall advertising market. Even so, their providers claim that they reach billions of users through tens of thousands of apps, suggesting that permission inheritance could operate at substantial scale. The supplied article does not name the affected apps or SDK providers, so their individual practices and responses cannot be assessed from this account.

Background, Android asks users to grant location access at the application level, but the EFF says there are no separate location permissions specifically for each SDK embedded inside an app. A person may therefore approve location use for an understandable feature, such as local weather forecasts or exercise-route tracking, without receiving a distinct choice about advertising-related collection. Developers may likewise assume the permission supports only their own feature when third-party components are receiving the same information. SDK vendors have a commercial incentive to collect data, while developers use their products to monetize otherwise free or inexpensive apps.

Why it matters, The factual concern extends beyond targeted advertising. According to the article, location histories gathered through this ecosystem can flow to data brokers and subsequently be sold to governments, militaries and intelligence or law-enforcement agencies, including the FBI. Stored location records also create exposure if a broker is breached or its information is stolen, something the report notes has happened to data brokers before. The EFF’s interpretation is that one app-level approval cannot amount to meaningful consent for separate collection and sharing by third-party advertising businesses. Users, app developers and organizations handling sensitive movements are all potentially affected.

What happens next, The EFF is urging Android developers to audit embedded SDKs and turn off location collection whenever it is unnecessary. That provides an immediate mitigation, but it depends on developers knowing which settings to inspect and actively changing defaults. The article does not report a platform-level change from Google, a regulatory action, or commitments from SDK providers, leaving it unclear whether permission design or default behavior will be revised. It is also uncertain how many apps currently transmit location in this manner because the EFF tested only part of the advertising ecosystem. Further audits, disclosures from SDK companies and clearer permission controls would be needed to establish the full scope.

Positives

  • The EFF used network-traffic analysis to identify which outside services were receiving location information, providing developers with a concrete method for investigating embedded SDK behavior.
  • The EFF gave developers an immediate mitigation by recommending that they disable unnecessary location collection in third-party SDK settings.
  • The findings bring attention to a permission-design gap after the EFF found that Android does not provide separate location approvals for individual SDKs inside an app.

Risks & concerns

  • Two Android apps identified by the EFF had a combined 60 million downloads while quietly transmitting users’ location information to third parties.
  • Advertising SDKs can inherit an app’s precise-location permission by default unless the developer actively disables collection, creating a risk that developers and users are unaware of the sharing.
  • The SDKs examined were only a small part of the advertising ecosystem but were promoted as reaching billions of users across tens of thousands of apps, indicating potentially broad exposure.
  • Location histories can pass through data brokers and be sold to governments, militaries and agencies such as the FBI, according to the article.
  • Data retained by brokers can be exposed through theft or hacking, and the article notes that some brokers have already experienced security incidents.
Primary sourceTechCrunchhttps://techcrunch.com/2026/08/04/android-app-developers-may-be-unwittingly-sharing-their-users-location-data-with-advertisers/
Read full article
Editorial note: Tech Beat summarizes and analyzes third-party reporting. The source link is the authoritative article. This page does not reproduce the full source text.

More From The Wire

CybersecurityAug 27

Visa VVAH AI Patches Code Before Human Review

Artificial IntelligenceAug 27

OpenAI Brings ChatGPT Ads to India With 50 Brands, ₹725 Daily Floor

Artificial IntelligenceAug 27

Nvidia Nears $12.9 Billion Hugging Face Acquisition Amid Conflicting Reports