Security0 views

Android Apps Secretly Sharing User Location Data With Advertisers

Android apps are leaking precise user location data to advertisers without developers' knowledge. The issue stems from advertising SDKs automatically inheriting location permissions that users grant to an app—unless developers explicitly disable this access in the code.

The problem affects major apps with significant user bases. QR Scanner and GPS Speedometer, which together account for 60 million downloads, were identified as examples of apps exposing location data this way. Because these permissions are inherited by default, location data flows to ad networks unless developers take deliberate action to prevent it.

The discovery highlights a gap between user expectations and actual data practices. When users grant an app permission to access location, they typically assume that permission applies only to the app's core functionality—not to third-party advertisers embedded within it. Without explicit developer intervention, advertising SDKs gain the same location access, creating an unintended privacy leak at scale.