All news
regulationcybersecurityproduct

EFF: Android SDKs May Leak User Location Data

08 Aug 2026

Android developers may be handing over more than they realize. New findings from the Electronic Frontier Foundation (EFF) warn that third-party SDKs (software development kits) embedded in Android apps can collect and share users' location data by default—frequently without the app developer's explicit knowledge or consent.

What EFF Found

According to EFF senior staff technologist Bill Budington, the SDKs examined in this research account for only a small slice of the broader advertising ecosystem, yet they claim to reach billions of users across tens of thousands of apps. In one striking example, EFF identified two Android apps—unnamed in the current findings—that were quietly sharing location data and had a combined 60 million downloads.

The core issue: Android does not offer SDK-specific location permissions. When a user grants an app permission to access location data, that same data can flow to any third-party SDK embedded within the app—including ad networks and analytics tools—without a separate consent step or visibility for the developer.

Why This Matters

The risks outlined by EFF extend beyond simple ad targeting:

  • Data broker exposure: Location data collected via SDKs can be sold to data brokers, who in turn may resell it to militaries, governments, and agencies including the FBI.
  • Expanded attack surface: Every additional party that touches location data increases the risk of hacking or theft, exposing users to privacy breaches.
  • Developer blind spots: Because there's no granular permission system for SDKs, developers may have limited ability to control—or even know—which location data is flowing to advertisers embedded in their own apps.

EFF's report frames this as a structural gap in Android's permission model rather than a case of isolated bad actors.

What's Still Unclear

Several important details remain unaddressed in the current findings:

  • The identities of the two apps with 60 million combined downloads have not been disclosed.
  • The specific SDKs or advertising companies involved are not named.
  • There is no clear guidance yet on how developers can detect or opt out of this SDK-level data sharing.
  • It's unknown whether Google or the Android platform has responded, or whether policy changes are planned.
  • The exact mechanism by which data brokers acquire and resell this data to government or military buyers hasn't been detailed.

Sources differ or are silent on these points, and EFF's disclosure appears to be an early warning rather than a full technical breakdown.

Why Founders Should Care

For early-stage founders building on Android, this report likely signals a few things worth acting on now rather than after a policy or legal shock:

  • Audit your SDKs: If your app integrates third-party ad or analytics SDKs, there's a reasonable chance you may be sharing more location data than you intend to—or than your privacy policy discloses.
  • Regulatory and reputational risk may be rising: As awareness of SDK-level data leakage grows, apps that can't clearly explain their data-sharing practices could face increased scrutiny from regulators, users, or press.
  • A platform-level gap may need to be your problem: Since Android currently lacks SDK-specific permissions, founders may need to build their own safeguards—such as vetting SDK partners or building internal data-flow monitoring—rather than relying on the OS to enforce boundaries.
  • This could open a market opportunity: The lack of tooling around SDK transparency suggests a possible opening for startups to build audit tools, privacy-focused SDK alternatives, or location-permission management solutions. Founders who move early here may be able to position privacy-first practices as a genuine product differentiator.

Nothing here confirms wrongdoing by any specific company, but the structural nature of the issue—no SDK-specific permissions, broad SDK reach across tens of thousands of apps—suggests this is unlikely to be a one-off concern. Founders shipping Android apps with embedded ad or analytics code may want to treat this as a prompt for a near-term technical and legal review.

Sources