VMTech
Discuss a project

Android advertising SDKs can inherit apps’ precise location access

Android advertising SDKs can inherit apps’ precise location access

The Electronic Frontier Foundation has found that some Android apps send users’ precise location data to third parties through embedded advertising software development kits. Two apps identified in its testing had been downloaded a combined 60 million times.

The sharing may occur without the app developer realizing it is enabled. When a user grants an app access to precise location, an embedded SDK can inherit that permission and collect the same information unless the developer actively disables the feature.

Why one permission can reach multiple parties

The EFF said Android has no SDK-specific location permissions. A person may therefore approve location access for a weather forecast, fitness route, or another core function, while advertising code inside the app receives the data as well.

“App-level location permissions alone cannot signal meaningful consent to location collection and sharing by third-party advertising SDKs.”

This gap matters because advertising SDK providers have a commercial incentive to encourage greater data collection. Although these SDKs are offered as a way for developers to monetize apps, location histories can flow to data brokers and subsequently be sold to militaries, governments, and intelligence agencies such as the FBI.

Location records also create security and privacy exposure if they are stolen or compromised. Some data brokers have already experienced such incidents, making unnecessary collection a risk even before considering how the information is commercially reused.

How the EFF identified the transfers

The organization analyzed app network traffic to determine which external services received users’ location data. Bill Budington, a senior staff technologist at the EFF, said the SDKs examined represent only a small share of the wider advertising ecosystem.

Even so, the companies behind those SDKs claim to reach billions of users across tens of thousands of apps. The figures do not establish that every user or app shares location, but they indicate the potential scale of permission inheritance within mobile advertising.

What development teams should review

The EFF urged app makers to disable unnecessary collection wherever possible and argued that sharing sensitive personal data should not be the default. For businesses maintaining Android products, that means treating third-party code as part of the application’s privacy and security boundary.

  • Inventory every advertising and analytics SDK embedded in the app.
  • Check which app permissions each component can inherit.
  • Analyze network traffic to confirm what data reaches external services.
  • Disable location collection that is not essential to the product’s function.

A permission prompt addressed to the app does not by itself explain every downstream recipient. The practical business implication is that Android teams must verify SDK behavior directly, align collection with the user-facing purpose, and remove default data flows that the product does not need.

#androidprivacy#appsecurity#locationdata#mobiledev
Open analytics
On the site 1 views
min read 3 05.08.2026
Instagram

Android advertising SDKs can inherit apps’ precise location access

Open the post on Instagram ↗