DMR News

Advancing Digital Conversations

Advertising SDKs May Share Android Users’ Precise Locations by Default

ByJolyen

Aug 6, 2026

Advertising SDKs May Share Android Users’ Precise Locations by Default

Some Android app developers may be sharing users’ precise locations with advertising companies without realising it, according to new research from the Electronic Frontier Foundation. The issue occurs when advertising software development kits inherit an app’s location permissions and transmit the information unless developers actively disable the collection.

Users may grant location access because an app needs it for a legitimate feature, such as weather forecasts, navigation or fitness tracking. However, Android does not provide separate location permissions for each third-party SDK embedded within an app, allowing advertising code to access the same information.

Four Advertising SDKs Collected Location by Default

The EFF examined the public documentation and network activity of several Android advertising SDKs. Its official report highlighted InMobi, BidMachine, Verve and Huawei’s Petal Ads for collecting or sharing location information by default when the host app had permission.

InMobi’s documentation stated that its SDK automatically forwards available location signals and encouraged developers to retain the setting because location-based advertising may produce higher revenue. BidMachine also collected location automatically, while Huawei’s developer materials promoted location access as a way to increase advertising income.

The EFF said these four SDKs represent only a small part of the wider advertising market. However, their providers claim collectively to reach billions of users through tens of thousands of apps.

Two Apps Had More Than 60 Million Downloads

Researchers analysed app network traffic to identify which outside services received location information. They found that QR Scanner and GPS Speedometer shared precise location data through BidMachine without displaying a separate notice or obtaining specific consent for the transfer.

The two apps had been downloaded more than 50 million and 10 million times, respectively. Their Google Play data-safety disclosures did not state that location information might be shared with third parties, according to the EFF.

Android defines precise location as usually accurate to within about 50 metres and sometimes within a few metres. Approximate access provides a broader estimate of about three square kilometres.

Location Data Can Reach Brokers and Government Agencies

Advertising platforms can include location information in real-time auctions used to sell ad placements. Data brokers may collect information from those transactions before selling access to customers that have included governments, law enforcement agencies and intelligence organisations.

The EFF said developers should review every third-party component in their apps and disable collection that is not required. Google’s Android guidance also advises developers to examine whether their SDK dependencies rely on location permissions and to minimise requests for sensitive information.

The organisation also called on advertising SDK providers to stop making location sharing the default. It said granting location access to an app cannot provide meaningful consent for undisclosed collection by separate advertising companies.


Featured image credits: StepSharp

For more stories like it, click the +Follow button at the top of this page to follow us.

Jolyen

As a news editor, I bring stories to life through clear, impactful, and authentic writing. I believe every brand has something worth sharing. My job is to make sure it’s heard. With an eye for detail and a heart for storytelling, I shape messages that truly connect.

Leave a Reply

Your email address will not be published. Required fields are marked *