{"id":2400,"date":"2025-03-06T10:10:01","date_gmt":"2025-03-06T10:10:01","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/03\/06\/google-silently-tracks-android-device-even-no-apps-opened-by-user\/"},"modified":"2025-03-06T10:10:01","modified_gmt":"2025-03-06T10:10:01","slug":"google-silently-tracks-android-device-even-no-apps-opened-by-user","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/03\/06\/google-silently-tracks-android-device-even-no-apps-opened-by-user\/","title":{"rendered":"Google Silently Tracks Android Device Even No Apps Opened by User"},"content":{"rendered":"<p>    Google Silently Tracks Android Device Even No Apps Opened by User<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Google collects and stores significant amounts of user data on Android devices, even when users haven\u2019t opened any Google apps.<\/p>\n<p>The study by Professor D.J. Leith from Trinity College Dublin, documents for the first time how pre-installed Google apps silently track users without seeking consent or providing any opt-out options.<\/p>\n<p>The research examined <a href=\"https:\/\/cybersecuritynews.com\/new-satanstealer-malware\/\" target=\"_blank\" rel=\"noreferrer noopener\">cookies<\/a>, identifiers, and other data stored on Android handsets by Google Play Services, the Google Play Store, and other pre-installed Google apps.<\/p>\n<p>Measurements were conducted using a Google Pixel 7 running Android 14 with the latest available builds of Google Play Services and Google Play Store apps.<\/p>\n<p>The findings by the SCSS analysts <a href=\"https:\/\/www.scss.tcd.ie\/Doug.Leith\/pubs\/cookies_identifiers_and_other_data.pdf\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">revealed<\/a> that Google servers send and store multiple tracking identifiers on handsets immediately after factory reset, before users ever interact with any Google app.<\/p>\n<p>These identifiers include advertising analytics cookies, links to track advertisement views and clicks, and persistent device identifiers that can uniquely identify both the device and user.<\/p>\n<p>Most concerning is that no consent is sought from users before storing any of this data, and there are currently no options to prevent this tracking.<\/p>\n<p>This behavior potentially violates EU data privacy regulations, particularly the e-Privacy Directive and possibly GDPR.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Tracking Mechanisms Revealed<\/strong><\/h2>\n<p>Several specific tracking technologies were identified in this study. The Google Android ID, a persistent device identifier, is stored in multiple locations including shared_prefs\/Checkin.xml and transmitted in numerous connections to Google servers.<\/p>\n<p>This identifier persists until a factory reset and is linked to the user\u2019s Google account upon login.<\/p>\n<p>DSID advertising analytics cookies are sent by googleads.g.doubleclick.net and stored in the Google Play Services data folder.<\/p>\n<p>When a user searches within the Google Play Store, \u201csponsored\u201d results contain tracking links that inform Google when clicked, which shows the connections fetching search results with embedded ad tracking links.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg6yvLWCxgHgt5L3yhVdBxu5h7BFFiOeVkvNMeNP0-JUfggOqPEh33mSdbsVWH71qVY-KeQnH1jvn7tJvpRMtk7TWr-5Vt2vZHweia4OqhtK2be779LbXWeyISxx6iWZ0wpWlqcuoeHPrkonidUVro8hQm2EQSrccvZPNMetFRJQzBq43qpZyLqtzL9wJw\/s16000\/%27Sponsored%27%2520results%2520contain%2520tracking%2520links%2520%28Source%2520-%2520SCSS%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">\u2018Sponsored\u2019 results contain tracking links (Source \u2013 SCSS)<\/figcaption><\/figure>\n<\/div>\n<p>The research also documented Google\u2019s use of NID cookies across multiple <a href=\"https:\/\/cybersecuritynews.com\/malicious-app-on-amazon-store\/\" target=\"_blank\" rel=\"noreferrer noopener\">apps<\/a>, server tokens for A\/B testing, and various authorization tokens that effectively log users into numerous Google services silently.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhCLQRsoNcS_tlwNW7dgZ6CjSLkGWkn6JfY_l4JP18XOnnbedAVf4AsUxlaCZh79upkOVoG6AB-5kVnx83od_lxRfSsP8Mv2gxOUZC20Q6PqfvUdwOOlwhqr3nUBL-gwiDVNvwfMYvjYyDm1XNkzZvoA_5s7kzKNSdGdtLYv5qv1j4ELOpWUALY3EzC3Cs\/s16000\/Google%2520Play%2520store%2520app%2520sending%2520user%2520interaction%2520data%2520to%2520Google%25E2%2580%2599s%2520Firebase%2520Analytics%2520server%2520region1.app-measurement.com%2520%28Source%2520-%2520SCSS%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Google Play store app sending user interaction data to Google\u2019s Firebase Analytics server region1.app-measurement.com (Source \u2013 SCSS)<\/figcaption><\/figure>\n<\/div>\n<p>Connections to Firebase Analytics servers were also observed transmitting user interaction data.<\/p>\n<p>\u201cUsers currently have little control over the data that apps store on an Android handset,\u201d notes Professor Leith in the study. \u201cThe main mitigations are to disable Google Play Services or the <a href=\"https:\/\/cybersecuritynews.com\/antidot-mobile-malware\/\" target=\"_blank\" rel=\"noreferrer noopener\">Google Play<\/a> Store app, but these are not practical options for most users.\u201d<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong><strong><code>Collect Threat Intelligence on the Latest Malware and Phishing Attacks with ANY.RUN TI Lookup -&gt;\u00a0<a href=\"https:\/\/intelligence.any.run\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=new-stegocampaign-attack&amp;utm_content=intelligence.any.run&amp;utm_term=040325\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try for free<\/a><\/code><\/strong><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/google-silently-tracks-android-device\/\">Google Silently Tracks Android Device Even No Apps Opened by User<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/google-silently-tracks-android-device\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Google Silently Tracks Android Device Even No Apps Opened by User Google collects and stores significant amounts of user data on Android devices, even when users haven\u2019t opened any Google apps. The study by Professor D.J. Leith from Trinity College Dublin, documents for the first time how pre-installed Google apps silently track users without seeking [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-2400","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2400"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=2400"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2400\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=2400"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=2400"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=2400"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}