An investigation by the Electronic Frontier Foundation (EFF) warns that some Android app developers may inadvertently expose users’ location data to advertisers. The EFF findings focus on how location permissions can be used not only by an app itself, but also by third-party software components developers include in their apps. According to the report, when users grant location access to an app, embedded third-party code can also obtain location information and potentially pass it along to advertising or other external parties.

The EFF’s goal is to alert developers and users that location sharing may occur through components integrated by the developer, even when the developer’s own app behavior does not explicitly target advertising. The outlets cite the investigation as evidence that developers may not be fully aware of what data their dependencies collect once permission is granted.

Both reports describe the issue as “inadvertent” sharing driven by third-party tracking or data collection. They also frame the findings as a prompt for greater scrutiny of third-party libraries and clearer disclosure of how location data is used within Android apps.