in ,

Android app developers may be unknowingly sharing user location data with advertisers

Android app developers may be unknowingly sharing user location data with advertisers

Many apps have good reasons to ask for your location. A weather app needs it to give you today’s forecast. A fitness app needs it to track your run.

But some apps do more than that. They quietly share your location with outside parties. This includes advertisers and data brokers. Often, the app’s own developer doesn’t even realize it’s happening. The data-sharing setting is simply turned on by default.

Hosting 75% off

New research from the Electronic Frontier Foundation looks into this problem. The EFF wants developers to understand a hidden risk. Some third-party code embedded in their apps can also collect location data. This happens automatically once a user grants location permission to the app itself.

This third-party code is often called an SDK, short for software development kit. Unless a developer manually disables it, the SDK inherits the app’s permissions. That means it can quietly gather a user’s precise location.

The EFF says many developers don’t realize this is happening. Their advice is simple. Turn off unnecessary data collection whenever possible.

Advertising SDKs are usually marketed as a way to make money from an app. But there’s a hidden cost. Users’ location histories end up in the hands of data brokers. Those brokers then sell the data. Buyers can include militaries, governments, and intelligence agencies. The FBI has reportedly purchased this kind of data too.

There’s also a security risk. If a data broker gets hacked, that location data can be exposed. This has already happened before. Some data brokers have suffered major breaches in the past.

The EFF looked closely at Android apps. It found several that were quietly sharing user location data. Two of those apps alone had a combined 60 million downloads.

To find this, the EFF analyzed the apps’ network traffic. This let them see exactly which outside services were receiving location data.

Read More: Google Rolls Out Age-Assurance Tools for Android Developers Globally

Bill Budington is a senior staff technologist at the EFF. He said that the SDKs they studied make up only a small slice of the wider ad industry. Even so, those SDKs claim to reach billions of users. They’re embedded across tens of thousands of apps. That gives a sense of how large this issue really is.

According to the EFF’s report, there’s no separate permission system for SDKs. Once a user allows an app to access their location, that access often extends to advertisers too. Companies that offer these SDKs are usually motivated to collect as much data as possible. That’s how they make money for their clients.

The EFF argues that app-level permissions aren’t enough. Users may agree to share their location with an app. That doesn’t mean they’ve agreed to share it with hidden third parties. The EFF says advertising SDKs shouldn’t default to data sharing, especially with something as sensitive as location.

Hosting 75% off

Written by Hajra Naz

SpaceX Doubles Revenue Through Anthropic, Google AI Compute Deals

SpaceX Doubles Revenue Through Anthropic, Google AI Compute Deals

Apple Says More Ex-Employees Leaked Data to OpenAI

Apple says more ex-employees may have leaked their confidential data to OpenAI