The Electronic Frontier Foundation warned that some Android apps have been quietly transmitting users’ precise location data to third-party advertising SDKs after users granted location access to the app itself. EFF said many developers may not realize embedded SDKs inherit the app’s permissions by default, allowing monetization components to collect and send sensitive location data unless developers explicitly disable that behavior.
The organization said it identified several affected Android apps with a combined about 60 million downloads, while cautioning that the exposed SDKs represent only a small slice of a broader ad-tech ecosystem that reaches billions of users. The data can flow to advertisers and data brokers and may be resold onward, including to governments or intelligence agencies, increasing surveillance, privacy, and breach risks; EFF argued that app-level consent does not amount to meaningful consent for third-party SDK collection and urged developers to turn off unnecessary location sharing.

See the reporting duties and controls this puts on the clock.
1 event from the most recent confirmed update back to the earliest known activity.
The Electronic Frontier Foundation reported that some Android apps were quietly sharing users' precise location data with third-party advertising SDKs by default after the apps received location permission. EFF said developers must explicitly disable this behavior and identified several affected apps totaling about 60 million downloads.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
4 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcescworld.com
Open sourcetechcrunch.com
Open sourceeff.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.