ThinkPatternGet the app
Story
TECHNOLOGY · AUG 4, 2026

EFF Report Warns Android SDKs Harvest Precise User Location Data

The Electronic Frontier Foundation warns that several Android advertising SDKs automatically share precise user location data with brokers and governments by default.

The Electronic Frontier Foundation released a report in August 2026 warning that several Android software development kits (SDKs) automatically collect and share users' precise location data with advertisers and data brokers. The investigation identified InMobi, BidMachine, Verve’s HyBid, and Huawei’s Petal Ads as libraries that inherit an app's location permissions by default. This allows the SDKs to transmit coordinates—sometimes accurate to within 10 feet—to thousands of third parties without the app developer's explicit knowledge or meaningful user consent.

Researchers observed the BidMachine SDK transmitting precise coordinates from apps like QR Scanner and GPS Speedometer, neither of which disclosed third-party sharing in the Google Play Store. The EFF found that some affected applications have been downloaded 60 million times. The organization warned that this sensitive data is often sold to intelligence agencies, the military, and the FBI for targeting and tracking operations.

In response, the EFF urged developers to vet their tools and called for U.S. legislators to implement federal privacy laws similar to GDPR. The report noted a gap in current protections, despite Google requiring data practice disclosures and the Federal Trade Commission issuing a 2024 order against InMarket for similar failures regarding informed consent for location data.


Reported across 6 outlets
Actors
Electronic Frontier FoundationGoogleFederal Trade Commission

Keep reading in the app

The full story and every source, free in the app.

Download on the App StoreComing soonGoogle Play