DistantNews
Support us
๐Ÿ‡น๐Ÿ‡ผ Taiwan /Technology

Android apps pose location data leak risk; two apps downloaded over 60 million times implicated

From Liberty Times · () Chinese

Translated from Chinese, summarized and contextualized by DistantNews.

At a glance

News Named sources Context piece
  • A study by the Electronic Frontier Foundation (EFF) found that some Android apps, via third-party SDKs, may collect user location data without explicit consent.
  • Two apps with over 60 million downloads were found to be sharing location data in the background.
  • Users are advised to review app permissions and limit location access, while developers are urged to disable unnecessary data collection.

Android users face a potential risk of their location data being leaked through third-party software development kits (SDKs) embedded in apps, according to a new study by the U.S. non-profit Electronic Frontier Foundation (EFF).

The EFF's research indicates that when users grant an app precise location permissions, the integrated SDKs can simultaneously collect this data. This often occurs without the app developers' explicit knowledge or consent, as the data collection feature may be enabled by default. Developers can disable this function, but many may not be aware it is active.

The problem lies in the third-party code used by many apps, which is the Software Development Kit (SDK). As long as the user agrees to the app accessing precise location, the SDK will usually obtain the same permission simultaneously.

โ€” Electronic Frontier FoundationThe EFF explained how location data can be collected by third-party SDKs within Android apps.

After analyzing network traffic from various Android apps, the EFF identified two applications with a combined download count exceeding 60 million that were covertly sharing user location data in the background. The EFF withheld the names of these apps, instead opting to alert developers to the issue and encourage them to audit their apps for unnecessary location data collection.

The advertising SDKs are a particular concern. While designed to help developers monetize their apps through advertising, they can also collect and share location data with third parties, significantly increasing the risk of privacy breaches. The EFF recommends that developers disable any non-essential location data collection features. For users, the advice is to regularly review app location permissions, avoid granting "precise location" access to apps that do not require it, and opt for "allow only while using the app" over "allow all the time."

The EFF recommends that developers disable non-essential location data collection features; general users should also regularly check app location permissions, and try not to enable 'precise location' for apps that do not require it, prioritizing 'allow only while using the app' over 'always allow'.

โ€” Electronic Frontier FoundationThe EFF provided advice for both developers and users on managing location data permissions.
DistantNews Editorial

Originally published by Liberty Times in Chinese. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.