HomeSecurityAndroid SDKs: Leaking user location to advertisers

Android SDKs: Leaking user location to advertisers

Advertising SDKs in Android apps can share users’ precise location with advertisers and data brokers without the developers’ knowledge — that’s the central finding of a new investigation by the Electronic Frontier Foundation (EFF) . The problem lies in the way Android SDKs inherit app permissions, meaning that granting location permission to an app automatically grants access to third-party code. The report comes at a time when mobile user privacy is under increasing pressure from regulators and security researchers worldwide.

See also: Official release of Android developer verification to all developers

Android SDKs leak user location to advertisers EFF
Android SDKs: Leaking user location to advertisers

According to TechCrunch, the EFF found that many Android embed third-party code — known as Software Development Kits (SDKs) — that is primarily used for ad management and data analysis. The problem is that these SDKs do not have separate access permissions on Android: once the user approves location access for the app, the third-party code automatically inherits the same access. Unless the developer explicitly disables location data collection by the SDKs, they will continue to send the data to the ad networks’ servers.

Bill Budington, a senior technologist at the EFF, said the SDKs examined represent a small percentage of the broader advertising ecosystem, yet they claim to reach billions of users through tens of thousands of apps. Among the apps found to be silently sharing location data, two had a combined 60 million downloads. The EFF conducted the tests by analyzing the apps’ network traffic and identifying which services were receiving users’ location data.

Android SDKs and location permission inheritance

The central technical issue highlighted in the EFF report is the lack of SDK-specific location permissions in Android . This means that Android ’s permission system doesn’t distinguish between the app’s own code and third-party code embedded in it. When a user taps “Accept” on a location access request, they’re essentially giving access to everything in the app — including advertising SDKs that they may not even know are there.

Advertising SDKs are marketed todevelopers as monetization tools: they allow free apps to generate revenue through ads without requiring the user to pay. However, the cost is the collection of location data, which is fed to data brokers who sell it to third parties. According to the EFF, these buyers can include the military, governments, intelligence agencies , and law enforcement agencies like the FBI. What’s more, this data poses a serious security risk if it’s compromised or stolen — something that has already happened to some data brokers.

Google asthe central gatekeeper of the Android, has already recognized the sensitivity of location data in advertising. AdMob states that publishers must provide notice and consent when transferring precise location data to Google for advertising purposes. However, this requirement does not automatically extend to all SDKs that may be embedded in the app.

See also: Flying Eagle Android RAT: Traces on 170 Servers

Digital Markets Act EU Google Android AI assistants access microphone camera

Android SDKs: Risks for users and developers

For users, the main risk is the creation of long-term location histories that reveal sensitive information: daily routines, home and work locations, visits to medical facilities, religious or political activities, and travel habits. The EFF has documented cases where location data from advertising sources has been used in ICE, global spying tools, revealing the identity of a priest, tracking union members, and tracking U.S..

For Android app developers, the risk is twofold. On the one hand, they could inadvertently violate privacy rules and be exposed to regulatory penalties. On the other hand, their reputation could be damaged if it is revealed that their app is sharing user data without explicit consent. The EFF points out that many developers believe that only their own code has access to location data, when in fact, the built-in SDKs receive the same data.

Statistically, the problem appears to be widespread. According to data from NowSecure from 2025, about 70% of Android apps tested contained both sensitive data and tracking domains, highlighting how widespread embedded tracking code is. It’s worth noting that similar patterns were also found in about three-quarters of iOS apps, suggesting that this is a problem across the entire mobile app industry, not just Android.

The EFF is clear in its position: “App-level location permissions cannot, by themselves, signal meaningful consent for location collection and sharing by advertising SDKsThe organization calls on developers to disable all unnecessary data collection and for SDKs not to make sharing personal data the default setting — especially for data as sensitive as location.

What Android SDKs developers need to do

Android app developers using advertising SDKs should immediately review the third-party libraries they have integrated into their apps. In particular, they are advised to review the settings of each SDK and explicitly disable location data collection where it is not necessary. They should also minimize the number of integrated SDKs and only choose those that offer transparency about data collection.

From a user perspective, the best advice is to carefully consider which apps have access to their precise location and opt for “Only when using” or “Approximate location” where possible. Android already offers the option to choose between precise and approximate location, and users should use this option consciously. Regularly reviewing app permissions from Android settings can also significantly reduce exposure to unwarranted data collection.

See also: Android's Find Hub now allows you to remove old Bluetooth headphones & earbuds

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Article image: Android 17 July update rolling out with four Pixel fixes

Overall, the EFF report highlights a structural weakness in Android ’s permissions model that affects millions of users worldwide. The solution is not simple, requiring coordinated action from Google , SDK providers , app developers, and regulators. However, the first step — raising developer awareness of the problem — is exactly what this report seeks to do. The push for greater transparency in advertising SDKs and stricter consent requirements is expected to intensify in the coming months, as regulators in the EU and the US turn their attention to the location data supply chain from mobile apps.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS