Android Apps Use Bluetooth and WiFi Scanning to Track Users Without GPS

Study Reveals Android Apps Collect Location Data via Bluetooth and WiFi Without User Consent
Photo: CyberInsider

Study Reveals Android Apps Collect Location Data via Bluetooth and WiFi Without User Consent

A recent study conducted by researchers from IMDEA Networks, Universidad Carlos III de Madrid, and the University of Calgary has uncovered that thousands of Android applications secretly collect user location data through Bluetooth and WiFi scanning. This allows continuous tracking and profiling without explicit user consent, despite Android’s privacy protections against direct GPS access.

The study analyzed 9,976 apps embedding 52 wireless-scanning SDKs, revealing that 86% of them collected at least one form of sensitive data, such as WiFi scan results or device identifiers. A significant portion of these SDKs engaged in ID bridging, linking resettable and persistent identifiers like Android Advertising IDs and WiFi MAC addresses, enabling long-term tracking even when users reset their privacy settings.

Notably, SDKs from companies like AltBeacon, Kochava, Salesforce Marketing Cloud, and Adobe Experience Platform were frequently embedded in these apps. Many of these tracking tools also integrate with advertising and analytics platforms, increasing data aggregation risks. Some SDKs even exploited Android vulnerabilities in unpatched devices to bypass Bluetooth and WiFi permission restrictions.

The study highlights how this covert data collection fuels a larger, unregulated location-tracking ecosystem, with companies selling harvested data to advertisers and even government agencies. Researchers recommend users disable Bluetooth and WiFi scanning when not in use, use privacy-focused Android ROMs, regularly review app permissions, and employ tracker-blocking tools to mitigate risks.

Leave a Reply

Your email address will not be published. Required fields are marked *