The U.S. military has disabled ad tracking on service members' devices after foreign adversaries exploited location data to target troops. A senator's letter confirms the action was taken in response to security threats.
The Department of Defense moved to cut off ad tracking capabilities following confirmed reports that hostile nations used location information gathered through mobile advertising networks to identify and target American military personnel.
Senator Ron Wyden disclosed the measure in a letter to military officials, stating that the tracking had created significant operational security vulnerabilities. Foreign adversaries, including Russia and China, have been known to purchase location data from commercial ad brokers to map U.S. military movements and identify bases and personnel.
How the vulnerability worked
Military service members' personal devices often run standard Android and iOS operating systems with default ad tracking enabled. Advertising networks collect precise location data from these devices, which is then sold to data brokers. Adversaries can purchase this data to track individual movements and patterns.
The practice raises broader cybersecurity concerns beyond military contexts. Commercial location data has become a standard commodity in the advertising industry, sold with minimal oversight or regulation.
Military response
The Pentagon's decision to disable ad tracking on troops' devices represents a direct policy response to an identified threat. The move aligns with growing scrutiny of data broker practices and their national security implications.
Wyden's letter indicates the military acknowledged the risk and took corrective action, though details on implementation timeline and scope remain limited. The measure applies to personal devices used by active-duty personnel.
Broader implications
The incident underscores how commercial data collection infrastructure creates security risks for government agencies and their employees. It also highlights the tension between the advertising industry's data practices and national security concerns.
Experts have long warned that location data represents a critical vulnerability, particularly for government and military personnel. The disclosure may prompt additional reviews of device security policies across federal agencies.
Attackers are actively exploiting a critical authentication bypass vulnerability in Citrix NetScaler, according to Previdian. CVE-2026-19490 allows threat actors to circumvent security controls on the widely-deployed application delivery platform.
A researcher known as Nightmare Eclipse has disclosed a CrowdStrike Falcon zero-day exploit called FalconFlank that enables privilege escalation on fully patched Windows systems. The vulnerability affects the widely-deployed endpoint protection software.
Google has released an emergency update for Chrome to fix a high-severity zero-day vulnerability in the V8 engine currently being exploited in attacks. The update addresses this flaw plus 11 additional vulnerabilities.
Hewlett Packard Enterprise has released a patch for a critical remote code execution vulnerability in ArubaOS-CX, its network operating system used in enterprise switches and wireless controllers.