New threat research finds third-party libraries inherit app permissions, enabling silent tracking flows to brokers, advertisers, and government buyers
The Electronic Frontier Foundation (EFF) has published new threat research revealing that some Android advertising software development kits are quietly passing users’ precise location information to advertisers and data brokers by default, even when app makers may not realize it is happening.
In a new report, the group says these third-party tools can inherit the host app’s location permission, so once a user approves access for the app itself, the embedded software development kit (SDKs) can begin collecting location data without asking again. According to TechCrunch, the EFF identified apps that had been downloaded a combined 60m times, and it traced the data flow by examining network traffic to see which services were receiving location information.
The EFF argues that Android’s permission system leaves a major blind spot because it asks for app-level consent, not SDK-specific consent. In the group’s view, that creates a mismatch: users may agree to share location with one app, but they are not clearly told that advertising libraries bundled inside that app may also receive the same data.
TechCrunch reported that SDK providers often have a business incentive to collect more information, and that location histories can later be sold through data brokers to advertisers, retailers, and government buyers, including the FBI and military intelligence.
The timing of the EFF report also adds to a tougher legal backdrop. Virginia has become the third US state to ban the sale of precise geolocation data, with the restriction taking effect 1 July 2026, and privacy laws such as the GDPR and California’s CCPA treat location data as highly sensitive personal information.
The EFF is urging developers to review their SDKs and turn off unnecessary collection, while privacy advocates are pressing for machine-readable disclosures that would make it easier for app stores and developer tools to audit third-party code.