EFF Investigation: Android Advertising SDKs Leak Precise Location to Data Brokers by Default
On August 4, 2026, the EFF published an investigation finding that at least four major Android advertising SDKs — InMobi, BidMachine, Verve's HyBid, and Huawei's Petal Ads — collect and share users' precise location w... The leaked location data, fed through real time bidding systems, has been used for ICE investiga...
Published byEdited with DeepSeek-V4-FlashImages generated with GPT Image 1.5
On August 4, 2026, the EFF published an investigation finding that at least four major Android advertising SDKs — InMobi, BidMachine, Verve's HyBid, and Huawei's Petal Ads — collect and share users' precise location w...
The leaked location data, fed through real time bidding systems, has been used for ICE investigations, global spy tools, and tracking union organizers and military personnel.
What new research has the Electronic Frontier Foundation published about Android advertising SDKs, and what does it reveal about how these SThe EFF investigation reveals a structural flaw in Android where embedded advertising SDKs inherit the app's location permission by default, enabling silent data sharing with data brokers.
AI Prompt
Create a landscape editorial hero image for this Studio Global article: What new research has the Electronic Frontier Foundation published about Android advertising SDKs, and what does it reveal about how these S. Article summary: On August 4, 2026, the Electronic Frontier Foundation (EFF) published a new investigation revealing that several major Android advertising SDKs collect and share users' precise location data with data brokers **by defaul. Topic tags: general, academic, general web, user generated, documentation. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, w
openai.com
On August 4, 2026, the Electronic Frontier Foundation (EFF) published a new investigation revealing that several major Android advertising SDKs collect and share users' precise location data with data brokers by default, exploiting a structural gap in Android's permission model where SDKs silently inherit the host app's location permissions unless the developer manually disables collection .
Studio Global AI
Continue your research
This page includes a source-backed answer you can continue inside Studio Global.
What is the short answer to "EFF Investigation: Android Advertising SDKs Leak Precise Location to Data Brokers by Default"?
On August 4, 2026, the EFF published an investigation finding that at least four major Android advertising SDKs — InMobi, BidMachine, Verve's HyBid, and Huawei's Petal Ads — collect and share users' precise location w...
What are the key points to validate first?
On August 4, 2026, the EFF published an investigation finding that at least four major Android advertising SDKs — InMobi, BidMachine, Verve's HyBid, and Huawei's Petal Ads — collect and share users' precise location w... The leaked location data, fed through real time bidding systems, has been used for ICE investigations, global spy tools, and tracking union organizers and military personnel.
EFF identified four advertising SDKs that collect and share precise location by default once the host app has location permission: InMobi, BidMachine, Verve's HyBid, and Huawei's Petal Ads.
These SDKs feed location data into real-time bidding systems, which location data brokers then harvest to build detailed movement profiles on hundreds of millions of people without meaningful user consent .
EFF's network traffic analysis found BidMachine's documentation was initially inaccurate about its location collection; BidMachine updated it only after EFF's technical analysis confirmed precise location was being transmitted by default .
InMobi was found to encourage developers to keep location sharing enabled by highlighting financial incentives in its documentation .
Location data sourced from this advertising pipeline has been used for ICE investigations, global spy tools, outing a gay priest, tracking union organizers, and tracking US military personnel .
Structural Weaknesses in Android's Permission Framework
The core problem is that Android's permission model does not distinguish between the app and the SDKs it contains. Once a user grants location permission to an app, any embedded third-party SDK automatically inherits that same permission .
Advertising SDKs typically have location-sharing settings that default to "on," meaning a developer who does not actively disable the feature unwittingly transmits users' precise GPS coordinates to ad networks and data brokers .
EFF notes that this design creates a blind spot: many developers integrate SDKs for monetization without realizing the SDK is exfiltrating location data by default, and the platform provides no granular mechanism to block SDK-level access while preserving the app's own location functionality .
An October 28, 2026 Google Play policy update will introduce a "location button" as the recommended minimum scope for precise location, but this change had not taken effect at the time of EFF's report, and it does not solve the SDK inheritance problem .
Regulatory Landscape: Virginia's 2026 Geolocation Data Sale Ban
On July 1, 2026, Virginia's amended Consumer Data Protection Act (VCDPA) took effect, prohibiting controllers from selling or offering for sale consumers' precise geolocation data (defined as location information accurate to within roughly 1,750 feet) .
Governor Abigail Spanberger signed Senate Bill 338 into law on April 13, 2026, making Virginia the third US state — after Maryland and Oregon — to enact such a ban .
The ban replaces the VCDPA's previous opt-out consent model with a flat prohibition on sale, but it does not directly restrict the default data-sharing pipeline EFF documented .
EFF's report highlights that even with state-level sale bans taking effect, the structural problem of default SDK collection persists, since the data can still be shared (as opposed to sold) and used for ad targeting without technically triggering the sale prohibition .
What EFF Recommends Developers Do
Disable unnecessary location collection. Developers must actively turn off location-sharing settings in advertising SDKs rather than relying on default configurations .
Review SDK documentation carefully. EFF found that some SDK documentation is inaccurate or deliberately downplays location collection; developers should perform their own technical testing to verify what data is being transmitted .
Choose SDKs with privacy-respecting defaults. EFF urges developers to select advertising libraries that do not collect location data by default and that provide clear, accurate documentation about data practices .
Adopt a data minimization approach. Developers should only grant location permission when the app's core functionality genuinely requires it, and should consider using approximate location instead of precise location where possible .
EFF Staff Technologist Lena Cohen stated: "Users can take extra steps to defend their location privacy, but they shouldn't have to. Developers, regulators, and legislators must act to stop apps from leaking users' location to advertising companies and data brokers" .
eff.org
Mobile Ad Software Encourages Location Data Sharing, ...