• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Tech

A Security Flaw in a Free Web Service Let Anyone Anonymously Track U.S. Cell Phones

By
David Z. Morris
David Z. Morris
Down Arrow Button Icon
By
David Z. Morris
David Z. Morris
Down Arrow Button Icon
May 19, 2018, 12:42 PM ET

A bug in the free demo version of a service called LocationSmart made it easy for a moderately savvy attacker to anonymously track the location of nearly any U.S. cell phone, before the bug was identified by a security researcher. The flawed tracking portal has since been shuttered, but the incident is a scary reminder that cell phones can be a major risk to personal security and privacy.

LocationSmart allows location tracking of phones on networks including AT&T, Sprint, T-Mobile, and Verizon. It normally requires that a phone’s owner consent to being tracked, and the company markets its service primarily to companies who want to keep track of their own workers, resources, or consenting customers.

But this week Robert Xiao, a PhD candidate at Carnegie Mellon University, told the security site KrebsOnSecurity that he had discovered a huge flaw in a demo tool that LocationSmart provided to potential customers. While the demo tool was supposed to require consent from the user being tracked, Xiao told KrebsOnSecurity that with “minimal effort” the tool could be used to “track most peoples’ cell phone without their consent.”

Get Data Sheet, Fortune’s technology newsletter.

Xiao and Krebs tested the exploit on several cell phone users, including one in Canada. In addition to finding the phones’ location to within 100 yards without the targets’ consent, the data could be plugged into Google Maps to determine the tracked phone’s direction of movement. (The tests were performed only after targets gave permission outside of the LocationSmart system). The exploit, which reportedly hinged on an insecure API feature, did not require that an attacker provide any of their own identity information.

In response to the report, LocationSmart issued a statement Friday saying that it has “resolved” the vulnerability and disabled the exploitable demo. The company also claims “the vulnerability was not exploited prior to May 16th and did not result in any customer information being obtained without their permission.”

The flaw was discovered, though, following reports that connected LocationSmart to another scary cell-tracking incident. On May 10th, the New York Times reported that a former Missouri sheriff had used a service provided by Securus Technologies to track the locations of private citizens without a court order. ZDNet then discovered that Securus was getting its data from LocationSmart.

About the Author
By David Z. Morris
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Hong Kong is the hub for China’s AI IPOs. It can be so much more than that
CommentaryHong Kong
Hong Kong is the hub for China’s AI IPOs. It can be so much more than that
By Brian Wong and Tony ChanMay 3, 2026
2 hours ago
Chinese court rules firms can’t lay off workers on AI grounds
AIChina
Chinese court rules firms can’t lay off workers on AI grounds
By Victor Swezey and BloombergMay 3, 2026
8 hours ago
jason corso
Commentarydisruption
AI models are choking on junk data
By Jason CorsoMay 3, 2026
10 hours ago
Sam Altman speaks into a microphone
AILabor
Sam Altman says the quiet part out loud, confirming some companies are ‘AI washing’ by blaming unrelated layoffs on the technology
By Sasha RogelbergMay 3, 2026
11 hours ago
Zoom is giving away $150K to ‘solopreneurs’ with no strings attached—as 33 million workers ditch corporate to become their own boss
SuccessCareers
Zoom is giving away $150K to ‘solopreneurs’ with no strings attached—as 33 million workers ditch corporate to become their own boss
By Orianna Rosa RoyleMay 3, 2026
16 hours ago
Disney’s new CEO is exploring a ‘super app’ for theme park tickets, movies and more
Big TechMedia
Disney’s new CEO is exploring a ‘super app’ for theme park tickets, movies and more
By Thomas Buckley, Lucas Shaw and BloombergMay 2, 2026
1 day ago

Most Popular

Scott Bessent on financial literacy: 'it drives me crazy' to see young men in blue-collar construction jobs playing the lottery
Personal Finance
Scott Bessent on financial literacy: 'it drives me crazy' to see young men in blue-collar construction jobs playing the lottery
By Fatima Hussein and The Associated PressMay 1, 2026
2 days ago
America got rich and got sad. A top economist says 2020 broke something that hasn't healed
Economy
America got rich and got sad. A top economist says 2020 broke something that hasn't healed
By Nick LichtenbergMay 3, 2026
12 hours ago
Gen Z is rebelling against the economy with ‘disillusionomics,’ tackling near 6-figure debt by turning life into a giant list of income streams
Economy
Gen Z is rebelling against the economy with ‘disillusionomics,’ tackling near 6-figure debt by turning life into a giant list of income streams
By Jacqueline MunisMay 2, 2026
1 day ago
China dominates the world's lithium supply. The U.S. just found 328 years' worth in its own backyard
North America
China dominates the world's lithium supply. The U.S. just found 328 years' worth in its own backyard
By Jake AngeloApril 30, 2026
3 days ago
I spent a decade selling homes to the ultra-wealthy. What I saw explains the housing market's nepo problem
Commentary
I spent a decade selling homes to the ultra-wealthy. What I saw explains the housing market's nepo problem
By Blake O'ShaughnessyMay 3, 2026
12 hours ago
The American household just took an 81% margin cut. Wall Street hasn’t priced it in
Commentary
The American household just took an 81% margin cut. Wall Street hasn’t priced it in
By Katica RoyMay 2, 2026
1 day ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.