Location Heartbleeding: The Rise of Wi-Fi Spoofing Attack Via Geolocation API
Xiao Han, Junjie Xiong, Wenbo Shen, Zhuo Lu, Yao Liu
Abstract
Location spoofing attack deceiving a Wi-Fi positioning system has been studied for over a decade. However, it has been challenging to construct a practical spoofing attack in urban areas with dense coverage of legitimate Wi-Fi APs. This paper identifies the vulnerability of the Google Geolocation API, which returns the location of a mobile device based on the information of the Wi-Fi access points that the device can detect. We show that this vulnerability can be exploited by the attacker to reveal the black-box localization algorithms adopted by the Google Wi-Fi positioning system and easily launch the location spoofing attack in dense urban areas with a high success rate. Furthermore, we find that this vulnerability can also lead to severe consequences that hurt user privacy, including the leakage of sensitive information like precise locations, daily activities, and demographics. Ultimately, we discuss the potential countermeasures that may be used to mitigate this vulnerability and location spoofing attack.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 286da0b4-c7e8-4f51-a8f3-e65f0e687580Cited by top-tier papers4
- Surveilling the Masses with Wi-Fi-Based Positioning SystemsErik C. Rye, Dave LevinS&P 2024 · 5 citations
- RøB: Ransomware over Modern Web BrowsersHarun Oz, Ahmet Aris, Abbas Acar, Güliz Seray Tuncay et al.USENIX Security 2023
- WILD Attack: Stealthy Undermining of Wi-Fi-Based Geolocation Through Remote Crowdsourced Data InjectionChangjia Zhu, Xiao Han, Parush Gera, Zhuo Lu et al.USENIX Security 2026
- A Systematic Threat Analysis and Practical Attacks on Automated Frequency Coordination SystemsYilu Dong, Tianchang Yang, Arupjyoti Bhuyan, Syed Rafiul HussainNSDI 2026
Related papers
- Non-cooperative wi-fi localization & its privacy implicationsAli Abedi, Deepak VasishtMobiCom 2022 · 30 citations
- IPvSeeYou: Exploiting Leaked Identifiers in IPv6 for Street-Level GeolocationErik C. Rye, Robert BeverlyS&P 2023
- GNSS-WASP: GNSS Wide Area SPoofingChristopher Tibaldo, Harshad Sathaye, Giovanni Camurati, Srdjan CapkunUSENIX Security 2025
- Practical Attacks Against Privacy and Availability in 4G/LTE Mobile Communication SystemsAltaf Shaik, Jean-Pierre Seifert, Ravishankar Borgaonkar, N. Asokan et al.NDSS 2016 · 342 citations
- Crowd-GPS-Sec: Leveraging Crowdsourcing to Detect and Localize GPS Spoofing AttacksKai Jansen, Matthias Schäfer, Daniel Moser, Vincent Lenders et al.S&P 2018 · 135 citations
