Many Android apps are quietly sharing users' precise location data with advertisers and data brokers — often without the developer even realizing it, according to new findings from the Electronic Frontier Foundation (EFF).

The EFF found that advertising software development kits (SDKs) embedded in apps inherit the app's location permission by default. Unless a developer actively switches the collection off, the SDK collects precise location data once the user grants permission to the app — a trade-off few users would knowingly accept.

"There are no SDK-specific location permissions," the EFF says. Once a user allows an app to access location, that data is shared with the ad SDK too. Among the apps identified, two had been downloaded a combined 60 million times. The SDKs examined claim to reach billions of users across tens of thousands of apps.

The location histories feed data brokers, who monetize the information and sell it on to customers that have included militaries, governments and intelligence agencies such as the FBI. The data is also a security and privacy risk if brokers are hacked, which some have experienced.

"App-level location permissions alone cannot signal meaningful consent to location collection and sharing by third-party advertising SDKs," the EFF wrote. "Advertising SDKs should not make sharing personal data the default, especially for data as sensitive as a person's location." The EFF urged app makers to disable unnecessary data collection wherever possible.