permissions

Winsage
August 13, 2026
The upcoming Patch Tuesday is scheduled for September 8th, 2026, during which Microsoft will address over 200 vulnerabilities across Windows platforms, including Windows 10, Windows 11, and Windows Server. Windows 10 users in the Extended Security Updates (ESU) program will receive updates until October 2027. Among the vulnerabilities, CVE-2026-68820 allows attackers to gain elevated privileges through the Windows auxiliary function driver for Winsock. Microsoft has identified 18 vulnerabilities as critical, including CVE-2026-62878, an RCE vulnerability in the Windows DNS server that can lead to a buffer overflow and code execution without user interaction. Another critical issue is CVE-2026-62893, a UAF vulnerability in the TFTP server of Windows Deployment Services, which allows code injection through UDP port 69. Additionally, CVE-2026-62815, an RCE vulnerability in Quick UDP Internet Connections (QUIC), permits code execution without user interaction, while CVE-2026-59124, although high risk, is not classified as critical due to the HPC Pack not being enabled by default.
Winsage
August 12, 2026
A security researcher named Nightmare Eclipse has discovered a vulnerability in Windows, called ShieldBreak, which allows hackers to gain system-wide access to users' devices and sensitive data by exploiting a flaw in Windows Defender. The vulnerability affects Windows 10, Windows 11 (including version 25H2), and Windows Server 2025. A proof-of-concept exploit has been provided, requiring users to run a Windows application to trigger the vulnerability. Security researcher Will Dormann confirmed that Windows Defender must be enabled for the exploit to work. Microsoft has not yet released a patch for ShieldBreak, which is classified as a zero-day vulnerability. This discovery follows previous vulnerabilities disclosed by Nightmare Eclipse, including RoguePlanet, for which Microsoft issued an inadequate patch. The situation has heightened tensions between the researcher and Microsoft regarding the handling of bug reports, especially after Microsoft threatened legal action against researchers disclosing zero-days outside established protocols. The disclosure of ShieldBreak occurred shortly after Microsoft's monthly security patch releases, which have been increasing in number.
AppWizard
August 9, 2026
Third-party advertising tools embedded in Android applications are automatically collecting location data, often without the app developers' awareness. Software development kits (SDKs) used for advertising come with location data collection enabled by default, unless developers actively disable this feature. Historical location data has been sold to military and intelligence agencies, including the FBI, and used in immigration enforcement actions in the US. The Electronic Frontier Foundation (EFF) reported that app-level location permissions do not provide meaningful consent for location collection by third-party advertising SDKs. The EFF identified four advertising SDKs—InMobi, BidMachine, Verve's HyBid, and Huawei's Petal Ads—that collect and share location data by default. Two analyzed apps had been downloaded 60 million times without providing a privacy notice or seeking user consent for third-party location sharing. Users can manage location permissions through their device settings, but the EFF emphasizes that developers should ensure user data is not shared by default.
AppWizard
August 6, 2026
A recent investigation by the Electronic Frontier Foundation (EFF) revealed that many Android applications contain third-party code that automatically transmits users' precise location data to external companies, including advertisers and data brokers, once location permission is granted. There are no specific location permissions for Software Development Kits (SDKs) on Android, meaning that granting one app access allows all bundled components to access the same data. Developers may be unaware that their apps are configured to share location histories with external firms, as advertising SDKs often prioritize data collection for revenue generation. The EFF calls for advertising SDKs to stop making personal data sharing the default setting and urges developers to disable unnecessary data collection. Location data can reach data brokers, which may experience breaches, compromising user privacy and security. This situation poses hidden risks for investors in the mobile advertising sector, as legal challenges and reputational damage may arise from regulatory scrutiny of location data practices. The EFF emphasizes that app-level permissions do not provide meaningful consent for third-party data sharing, highlighting the value and risks associated with location data.
AppWizard
August 6, 2026
A report from the Electronic Frontier Foundation (EFF) highlights concerns about third-party software development kits (SDKs) in mobile applications collecting and sharing user location data with advertising companies, often without user consent. Many developers use these advertising SDKs for monetization, but their default settings allow for location data collection. This data is sent to advertising companies and location data brokers, which can misuse it in sensitive contexts. Users may unknowingly expose their location data when granting permissions to apps, as third-party SDKs can access this information without clear user awareness. The EFF identified several advertising SDKs, including InMobi, BidMachine, Verve’s HyBid, and Huawei’s Petal Ads, that collect and share location data by default. Developers are encouraged to review SDK settings to protect user privacy, and the EFF calls for regulatory scrutiny of data harvesting practices.
AppWizard
August 5, 2026
Advertising companies provide software development kits (SDKs) for mobile app monetization, which often automatically transmit users' location data to ad systems and location data brokers, raising privacy concerns. Many developers and users may be unaware of this data sharing. When developers allow SDKs to collect location data, it poses risks beyond targeted ads, including potential misuse by agencies like ICE and global surveillance. Location data brokers harvest precise movements of individuals, often without their consent, through mobile applications. Some apps directly collaborate with data brokers, while others leak data through advertising SDKs during real-time bidding (RTB) auctions. An incident in 2025 revealed that many apps unknowingly contributed to a location data broker's database. Developers must understand their SDKs' location-sharing practices to mitigate risks. Advertising SDKs can collect location data automatically once users grant permission, without specific permissions for the SDKs themselves. Precise location data can be collected when apps have location permissions, leading to potential privacy violations. Several SDKs have been identified as collecting location data by default, increasing the risk of unintentional data leaks. The Electronic Frontier Foundation (EFF) found that four advertising SDKs collect users' location data by default when location permissions are granted. InMobi encourages location sharing for higher revenue, while BidMachine updated its documentation after EFF's inquiry, confirming precise location data collection. Verve's SDK also collects location data by default but presents a cautious narrative in its Play Store guidance. Huawei's SDK recommends obtaining location permissions to enhance revenue, with default location sharing occurring if permissions are granted. Location data can be shared without users' knowledge or meaningful consent, complicating informed consent issues. The focus on four SDKs does not imply that others adequately protect location data, as many have faced criticism for similar practices. Studies indicate that SDKs often encourage increased data collection through design and documentation, leading to minimal control for developers over data transmission. The EFF's analysis highlights that advertising SDKs incentivize location data sharing through default settings and unclear documentation. Developers should assess third-party SDKs and disable unnecessary data collection. Regulators must hold developers accountable for unlawful data sharing, while legislators should enact laws to protect location privacy and address online behavioral advertising, which drives data tracking.
Search