A bug in the website of LocationSmart, which sells real-time phone location data, let anyone track people's locations across North America without consent
The bug allowed one Carnegie Mellon researcher to track anyone's cell phone in real time. — A company that collects the real …
Context & Ripple Effects
LocationSmart sits at the center of a commercial pipeline the related coverage has been mapping all week: it holds direct connections to major US carriers including AT&T and Verizon and sells millions of Americans' real-time phone locations to third parties. Days earlier, reporting had already tied the same data flows to prison-phone vendor Securus in a scandal over dealers of Americans' real-time cell location.
The new disclosure changes the story from 'who buys this data' to 'who can take it': a single Carnegie Mellon researcher used a bug on LocationSmart's own website to pull real-time locations across North America with no consent and no account — meaning the aggregation layer itself was an open door, not just its customer list.
First-order effects
- Anyone who visited the flawed website could query the real-time location of a phone number across North America without consent, turning LocationSmart's carrier-fed product into a public tracking tool until the bug was closed.
Second-order effects
- AT&T, Verizon, and the other carriers feeding LocationSmart now wear the exposure: their subscribers' coordinates passed through an intermediary whose own web security failed a single researcher's test, forcing carriers to defend or sever these aggregator relationships.
- The Securus parallel means every buyer in the location-broker market faces the same question — if one dealer's front end was this porous, what does the rest of the supply chain look like?
Third-order effects
- The pattern holds across the corpus: consumer GPS trackers later shown to leak locations and activate microphones (flaws in trackers marketed for elderly and kids), a leaked dataset logging 12M+ Americans' movements via 50B pings, and by 2026 ad-based systems like Webloc streaming records from up to 500M devices — pointing toward regulation that treats real-time location as a protected class of data rather than an ordinary commercial commodity.
The trend: Real-time phone location is moving from a quietly sold carrier commodity to a regulated liability, as each breach — broker bugs, tracker flaws, leaked ping logs — exposes how little consent or security governs the supply chain.