Monday, October 5, 2026

Google Secretly Tracks Android Devices Even Without User-Opened Apps

A recent technical study conducted by researchers at Trinity College Dublin has revealed that Google collects and stores extensive user data on Android devices, even when pre-installed Google apps are never opened.

The findings indicate that cookies, device identifiers, and tracking links are downloaded and stored without user consent, raising significant privacy concerns.

Persistent Tracking Without User Interaction

The study uncovered that Google Play Services, the Google Play Store, and other pre-installed apps silently store various types of data on Android devices.

This includes advertising analytics cookies, tracking links for advertisements, and persistent device identifiers such as the Google Android ID.

These identifiers are transmitted to Google servers even when the device is idle after a factory reset and without any explicit user interaction.

For instance, the DSID cookie, a key component of Google’s advertising analytics system, is downloaded immediately after a user logs into their Google account.

This cookie is linked to the user’s account and is used to track interactions across apps and services.

Similarly, the Google Android ID, a persistent device identifier, is assigned upon device setup and transmitted in multiple connections to Google servers.

Lack of Transparency and Consent

The study highlights that no consent is sought from users for storing this data, nor are users provided with an opt-out mechanism.

Most of the collected data is not strictly necessary for the functioning of services explicitly requested by users.

For example:

  • Advertising tracking links stored by the Google Play Store app are used to monitor user clicks on sponsored search results.
  • ServerLogs cookies, downloaded during app usage, tag user interactions with unique identifiers linked to their accounts.
  • Experiment tokens used for A/B testing of app updates are stored and transmitted alongside telemetry data without user knowledge.

Even sensitive data related to advertising or app usage is collected without clear documentation or purpose statements from Google.

Potential Violations of Privacy Regulations

The findings suggest potential violations of European Union (EU) privacy laws, including the ePrivacy Directive and General Data Protection Regulation (GDPR).

Under these laws, explicit user consent is required before storing or processing personal data.

The study notes that much of the collected data can be used to uniquely identify devices and users, making it subject to GDPR regulations.

Users have minimal control over the data stored by Google apps.

While it is possible to clear app data via device settings, there is no option to selectively delete cookies or prevent their storage entirely.

Disabling Google Play Services or the Play Store app two primary sources of data collection is impractical for most users due to their dependency on third-party apps.

The researchers informed Google about their findings prior to publication.

However, Google declined to comment on the legal implications or address whether changes would be made to its data collection practices.

The company did not dispute any of the technical observations reported in the study.

This study sheds light on previously undocumented practices of pre-installed Google apps on Android devices.

It underscores the urgent need for greater transparency in how user data is handled and raises questions about similar practices on other platforms, such as Apple’s iOS.

The researchers call for further investigations into these issues and advocate stricter enforcement of privacy regulations globally.

This revelation serves as a reminder for users to remain vigilant about their digital privacy while prompting regulators to scrutinize tech giants’ compliance with privacy laws.

Are you from SOC/DFIR Teams? – Analyse Malware Incidents & get live Access with ANY.RUN -> Start Now for Free.

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

GlassWorm Supply Chain Attack Hides Malware Inside VS Code Color Themes

A GlassWorm-linked software supply chain campaign has abused seemingly...

Attackers Abuse Legitimate ScreenConnect Client in Phishing Campaign to Gain Remote Access

Threat actors are increasingly bypassing conventional malware detection by...

Microsoft Releases Emergency Exchange Server Update to Fix CVE-2026-96940

Microsoft has released a revised security update package for...

South Korea Orders Investigation Into AI-Powered Cyberattacks on Major Banks

South Korean President Lee Jae Myung has ordered a...

Google PageBreak AI Agent Finds Over 500 XSS Vulnerabilities Across Its Web Applications

Google has disclosed that PageBreak, an internal AI security...

Citrix NetScaler SAML Vulnerability Enables Unauthenticated Remote DoS Attacks

Citrix has released emergency security updates to address a...

Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices

A newly identified IoT botnet, Cling, disguises its command-and-control...

Microsoft Warns ClickFix Attacks Use Fake CAPTCHA Lures to Execute Malicious Commands

Microsoft Threat Intelligence has identified a ClickFix campaign in...

Related Articles

Recent News