Millions of Android users are having their precise location data quietly shared with advertisers and government agencies because third-party software development kits (SDKs) inherit app permissions by default, according to a new investigation by the Electronic Frontier Foundation (EFF).
While granting location access makes perfect sense for utilities like weather forecasts or fitness tracking, many app developers remain unaware that they are simultaneously broadcasting this sensitive information to external entities. This silent sharing occurs because the default configurations within third-party code snippets are often pre-set to harvest and transmit user data.
How Silent Data Sharing Exploits App Permissions
The core of the issue lies in the integration of software development kits (SDKs)—pre-packaged code blocks that developers use to add features or advertising networks to their apps. New findings by the Electronic Frontier Foundation warn creators that these embedded tools inherit the parent app’s permissions. Unless a developer manually opts out and deactivates this setting, the SDK automatically begins gathering precise coordinates the moment a user grants location access to the app itself.
The EFF highlights that a vast number of developers are completely oblivious to this default behaviour. Consequently, the privacy advocacy group is urging mobile creators to audit their software and disable unnecessary data harvesting mechanisms immediately.
The Dark Web of Data Brokers and Government Buyers
Although advertising SDKs are marketed as straightforward tools for developers to monetise their free applications, the societal cost is steep. User location histories are routinely funnelled to data brokers who package and sell this highly personal intelligence. This data eventually reaches commercial buyers, militaries, national governments, and intelligence agencies, including the FBI. Beyond state surveillance, storing vast databases of historical location coordinates poses a massive security threat, particularly as several prominent data brokers have previously suffered catastrophic data breaches.
Massive Scale: 60 Million Downloads Affected
To demonstrate the severity of the leak, the EFF analysed network traffic to trace exactly where user location packets were being sent. The investigation flagged several popular Android applications actively transmitting coordinates to third-party services. Among those identified were two specific apps that have accumulated a combined total of over 60 million downloads to date.
Bill Budington, a senior staff technologist at the EFF, told TechCrunch that whilst the specific SDKs analysed represent only a small fraction of the global advertising ecosystem, they still claim a footprint that reaches billions of devices across tens of thousands of applications. This highlights the staggering, systemic scale of modern location surveillance.
The Call for Urgent Developer Action
A fundamental flaw in mobile operating systems exacerbates this issue: there are currently no SDK-specific location permissions. Once a user trusts an app with their location, that trust is automatically extended to every third-party library running inside it. Because the companies providing these SDKs are commercially incentivised to hoard as much consumer data as possible, they rarely build privacy-first defaults.
The EFF maintains that app-level permissions are entirely inadequate for establishing meaningful user consent for third-party tracking. The group asserts that advertising SDKs must stop making personal data extraction the default state, especially when dealing with data as sensitive as a person’s physical movements.
