• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Tech

A Security Flaw in a Free Web Service Let Anyone Anonymously Track U.S. Cell Phones

By
David Z. Morris
David Z. Morris
Down Arrow Button Icon
By
David Z. Morris
David Z. Morris
Down Arrow Button Icon
May 19, 2018, 12:42 PM ET

A bug in the free demo version of a service called LocationSmart made it easy for a moderately savvy attacker to anonymously track the location of nearly any U.S. cell phone, before the bug was identified by a security researcher. The flawed tracking portal has since been shuttered, but the incident is a scary reminder that cell phones can be a major risk to personal security and privacy.

LocationSmart allows location tracking of phones on networks including AT&T, Sprint, T-Mobile, and Verizon. It normally requires that a phone’s owner consent to being tracked, and the company markets its service primarily to companies who want to keep track of their own workers, resources, or consenting customers.

But this week Robert Xiao, a PhD candidate at Carnegie Mellon University, told the security site KrebsOnSecurity that he had discovered a huge flaw in a demo tool that LocationSmart provided to potential customers. While the demo tool was supposed to require consent from the user being tracked, Xiao told KrebsOnSecurity that with “minimal effort” the tool could be used to “track most peoples’ cell phone without their consent.”

Get Data Sheet, Fortune’s technology newsletter.

Xiao and Krebs tested the exploit on several cell phone users, including one in Canada. In addition to finding the phones’ location to within 100 yards without the targets’ consent, the data could be plugged into Google Maps to determine the tracked phone’s direction of movement. (The tests were performed only after targets gave permission outside of the LocationSmart system). The exploit, which reportedly hinged on an insecure API feature, did not require that an attacker provide any of their own identity information.

In response to the report, LocationSmart issued a statement Friday saying that it has “resolved” the vulnerability and disabled the exploitable demo. The company also claims “the vulnerability was not exploited prior to May 16th and did not result in any customer information being obtained without their permission.”

The flaw was discovered, though, following reports that connected LocationSmart to another scary cell-tracking incident. On May 10th, the New York Times reported that a former Missouri sheriff had used a service provided by Securus Technologies to track the locations of private citizens without a court order. ZDNet then discovered that Securus was getting its data from LocationSmart.

About the Author
By David Z. Morris
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

When AI sells to AI, brands win on data and identity 
Future of WorkCommentary
When AI sells to AI, brands win on data and identity 
By Jarrod MartinApril 13, 2026
5 minutes ago
China went from uninvestable to unavoidable—and Hong Kong is cashing in with a slew of AI-centric IPOs
NewslettersTerm Sheet
China went from uninvestable to unavoidable—and Hong Kong is cashing in with a slew of AI-centric IPOs
By Nicholas GordonApril 13, 2026
1 hour ago
Apple CEO Tim Cook in Davos on January 21, 2026. (Photo: Mandel Ngan/AFP/Getty Images)
NewslettersFortune Tech
Apple smart glasses are coming into view
By Andrew NuscaApril 13, 2026
4 hours ago
Blazing hot IPOs, an AI agent craze, and a new word for ‘token’: Here’s what’s happening in the world of Chinese AI
AsiaChina
Blazing hot IPOs, an AI agent craze, and a new word for ‘token’: Here’s what’s happening in the world of Chinese AI
By Nicholas GordonApril 12, 2026
16 hours ago
Intuit was an AI pioneer. Why its stock became a SaaSpocalypse casualty
InvestingSoftware
Intuit was an AI pioneer. Why its stock became a SaaSpocalypse casualty
By Geoff ColvinApril 12, 2026
21 hours ago
Artemis III will practice docking Orion with lunar landers in Earth orbit next year while Musk’s Starship and Bezos’ Blue Moon compete for Artemis IV
InnovationNASA
Artemis III will practice docking Orion with lunar landers in Earth orbit next year while Musk’s Starship and Bezos’ Blue Moon compete for Artemis IV
By Marcia Dunn and The Associated PressApril 12, 2026
21 hours ago

Most Popular

'This is the last warning.' Iran threatens U.S. warships after they throw down the gauntlet for winner-take-all Strait of Hormuz
Politics
'This is the last warning.' Iran threatens U.S. warships after they throw down the gauntlet for winner-take-all Strait of Hormuz
By Fortune EditorsApril 11, 2026
2 days ago
'People are trying to be creative': Tariff-battered American companies are so cash-starved they are using refund claims as collateral for loans
Economy
'People are trying to be creative': Tariff-battered American companies are so cash-starved they are using refund claims as collateral for loans
By Fortune EditorsApril 12, 2026
1 day ago
A 93-year-old refused to sell her home to the Masters golf course that’s spent $280 million on expansion: ‘Money ain’t everything’
Real Estate
A 93-year-old refused to sell her home to the Masters golf course that’s spent $280 million on expansion: ‘Money ain’t everything’
By Fortune EditorsApril 12, 2026
1 day ago
Here's how a U.S. naval blockade of the Strait of Hormuz could work. 'This is a big task, and it's a big gamble'
Politics
Here's how a U.S. naval blockade of the Strait of Hormuz could work. 'This is a big task, and it's a big gamble'
By Fortune EditorsApril 12, 2026
19 hours ago
The 'affordability economy' has created a housing market nobody predicted: Prices collapsing in the Sun Belt, soaring in the Rust Belt
Real Estate
The 'affordability economy' has created a housing market nobody predicted: Prices collapsing in the Sun Belt, soaring in the Rust Belt
By Fortune EditorsApril 11, 2026
2 days ago
Palantir CEO says AI ‘will destroy’ humanities jobs but there will be ‘more than enough jobs’ for people with vocational training
Future of Work
Palantir CEO says AI ‘will destroy’ humanities jobs but there will be ‘more than enough jobs’ for people with vocational training
By Fortune EditorsApril 11, 2026
2 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.