Saturday, December 28, 2024
HomeSecurity NewsGoogle Collects Android Users Location Even though you have Turnoff Location Services

Google Collects Android Users Location Even though you have Turnoff Location Services

Published on

SIEM as a Service

Android phones collecting users location data even when you are offline and send it back to google once you have connected to the Internet. Even though if you have turned off Location services or removed SIM card.

Starting from 2017 Android phones started collecting address of nearby cellphone towers even if you turn off location services and send back to Google once you come online, according to Quartz investigation.

Quartz contacted Google and they confirmed the practice. According to Google Spokesperson Google uses to manage push notifications and messages on Android phones for the past 11 months. He also added they never used or stored data.

Devices that connected to mobile data or WiFi use to send data to Google whenever they come across with a new cell tower. Quartz observed even after default factory reset and apps with location service disabled it continues to send nearby cell tower address to Google.

- Advertisement - SIEM as a Service

It is still unclear how the cell tower address transmitted as a data string will improve the message delivery and not limited to any particular type of Android phone or tablet; Google was apparently collecting cell tower data from all modern Android devices before being contacted by Quartz.

The practice is annoying and it breaks the user’s privacy. Anyway the data sent is encrypted, but still, it can be potentially used if the device is compromised with Spyware.

Also Read Interesting to See How Google Recognize Traffic Condition

Nowadays it is not a surprise to see a malicious app on Google play store, hackers continued to deceive the Google safety checks even after Google play protect implementation.

Google’s privacy policy says that they can collect the information from devices that use services, but not indicates they can collect even if the location sharing is disabled.
When you use Google services, we may collect and process information about your actual location. We use various technologies to determine location, including IP address, GPS, and other sensors that may, for example, provide Google with information on nearby devices, Wi-Fi access points, and cell towers.

There is no way for users to turn off the collection of cell tower data, according to Google they are to end the practice by end of this month and Android phones will no longer send cell-tower location data to Google.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Lumma Stealer Attacking Users To Steal Login Credentials From Browsers

Researchers observed Lumma Stealer activity across multiple online samples, including PowerShell scripts and a...

New ‘OtterCookie’ Malware Attacking Software Developers Via Fake Job Offers

Palo Alto Networks reported the Contagious Interview campaign in November 2023, a financially motivated...

NjRat 2.3D Pro Edition Shared on GitHub: A Growing Cybersecurity Concern

The recent discovery of the NjRat 2.3D Professional Edition on GitHub has raised alarms...

Palo Alto Networks Vulnerability Puts Firewalls at Risk of DoS Attacks

A critical vulnerability, CVE-2024-3393, has been identified in the DNS Security feature of Palo...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

North Korean Hackers Stolen $2.2 Billion From Crypto Platforms In 2024

Cryptocurrency hacking incidents in 2024 surged 21.07% YoY to $2.2 billion, with 303 breaches...

Deloitte Denies Breach, Claims Only Single System Affected

Ransomware group Brain Cipher claimed to have breached Deloitte UK and threatened to publish...

Poison Ivy APT Launches Continuous Cyber Attack on Defense, Gov, Tech & Edu Sectors

Researchers uncovered the resurgence of APT-C-01, also known as the Poison Ivy group, an...