EFF Report: Mobile Ad SDKs Are Silently Sharing User Location Data
Many mobile advertising software development kits (SDKs) automatically funnel user location data to data brokers without the user's knowledge or meaningful consent. These SDKs facilitate data sharing through privacy-invasive defaults, financial incentives, and obscure documentation, often bypassing proper user authorization. The Electronic Frontier Foundation (EFF) warns that developers risk inadvertently exposing sensitive user information if they do not explicitly configure or disable these location-sharing features. Identified SDKs EFF researchers analyzed dozens of SDKs and highlighted four that share location data by default whenever a user grants app location permissions: InMobi BidMachine Verve’s HyBid Huawei’s Petal Ads Risks of Data Exposure Beyond targeted advertising, location data sourced from these libraries has been exploited for invasive surveillance, including: ICE investigations Global espionage tools Outing gay individuals Tracking union organizers Monitoring U.S. military personnel Call to Action Developers: Must scrutinize SDK settings and take responsibility for protecting user data rather than relying on default library configurations. Regulators and Legislators: Urged to implement stricter enforcement and policies to prevent apps from leaking location data to brokers and advertising networks.
EFF Deeplinks ·