Ad SDK Defaults Leak Location Beyond App Controls

The app’s location permission can end up feeding a second system the user never sees. In these Android ad stacks, the SDK can turn one granted permission into a standing stream to brokers and advertisers, outside the app’s own privacy settings. EFF reviewed public developer docs for dozens of widely used ad SDKs and identified four that collect and share location by default when an Android app has location permission: InMobi, BidMachine, Verve’s HyBid, and Huawei’s Petal Ads. The report says the behavior is reinforced by privacy-invasive defaults, financial incentives, and unclear documentation, so developers may expose location data without realizing the broker-facing feed exists. The risk persists after the app owner thinks they have controlled the setting, because the sharing path lives in the embedded SDK. That creates a third-party location dataset that can outlast the app’s own UI choices and user understanding.

Part of the PlainSec briefing for 2026-08-05

Editions

Sources