Mobile carriers possess a silent capability to extract precise GPS coordinates from any smartphone without user notification, consent, or operating system awareness.
This functionality operates through cellular protocols RRLP (Radio Resource Location Protocol) and LPP (LTE Positioning Protocol), which enable control-plane positioning at the baseband processor level, completely bypassing Android and iOS location permissions.
The Architecture Behind Invisible Tracking
Flowchart of RRLP location request signaling from GMLC to SMLC and mobile station in 3G networks
Modern smartphones contain two distinct processors: the application processor (AP) running the operating system and apps, and the baseband processor (BP) managing cellular modem firmware and radio communications.
These processors operate in isolation, with the baseband functioning as a proprietary black box running its own real-time operating system.
When carriers issue location requests, they communicate directly with the baseband processor through control-plane signaling channels used for network infrastructure management, never alerting the application processor that enforces user permissions.
The Serving Mobile Location Centre (SMLC) within the carrier network initiates positioning requests via control-plane channels.
The baseband processor receives these commands, activates the GPS chipset, calculates coordinates, and transmits results back to the network.
Throughout this entire process, the application processor and consequently all OS-level location permissions remain completely uninvolved and unaware.
Flowchart of RRLP location request signaling from GMLC to SMLC and mobile station in 3G networks
LTE control-plane location services signaling flow with LPP transport
RRLP, standardized in 3GPP TS 04.31 for GSM and UMTS networks, supports two positioning methods: MS-Assisted mode, where phones send raw GPS measurements for network-side position calculation, and MS-Based mode,e where phones compute complete GPS fixes and return finished coordinates.
In MS-Based positioning, networks first provide assistance data, including satellite ephemeris, reference time, and approximate position, to accelerate GPS acquisition before receiving precise location responses.
LPP, defined in 3GPP TS 36.355 for 4G and 5G networks, expands upon RRLP with additional positioning methods including OTDOA (Observed Time Difference of Arrival), ECID (Enhanced Cell ID), and 5G Release 16+ NR positioning capable of sub-meter accuracy.
Despite enhanced capabilities, the fundamental architecture remains identical: network queries reach the baseband directly, which responds without OS mediation.
RRLP contains a critical security flaw that requires no authentication. Phones do not verify whether location requests originate from legitimate emergency services, authorized legal processes, or rogue actors.
Security researcher Harald Welte demonstrated this vulnerability at HAR2009, proving smartphones would surrender GPS coordinates to any entity transmitting properly formatted RRLP requests via fake base stations.
Originally designed for E911 emergency services mandated by the FCC, these protocols have been repurposed far beyond emergency response.
DEA documents obtained through FOIA requests reveal carrier-assisted GPS tracking of suspects since 2006, using court orders or subpoenas. While the 2018 Carpenter v.
United States Supreme Court ruling established warrant requirements for historical cell-site location data; real-time control-plane positioning occupies a legal gray area with inconsistent standards across jurisdictions.
During the COVID-19 pandemic, Israel’s Shin Bet intelligence agency deployed carrier location data for mass surveillance of infected individuals and contacts, demonstrating how existing infrastructure enables rapid surveillance activation through policy decisions rather than technical implementation.
In 2019, major US carriers, including T-Mobile, AT&T, and Sprint, were exposed selling real-time location data to third-party aggregators like LocationSmart and Zumigo, who resold access to bail bond companies and bounty hunters.
The FCC imposed over $200 million in fines, yet the underlying silent positioning capability remains fully operational.
Application-layer privacy controls prove completely ineffective against control-plane positioning. Airplane mode blocks cellular connectivity entirely, but iOS and Android location permissions, Location Services toggles, VPNs, and firewalls operate at API and IP layers that control-plane signaling bypasses entirely.
The baseband processor maintains direct hardware access to GPS chipsets independent of OS oversight.
Apple’s iPhone 16e featuring the custom C1 modem represents the first genuine mitigation. iOS 26 introduces Location Privacy features providing visibility into control-plane requests, user consent prompts, and options to downgrade precise GPS to coarser cell-tower estimates.
However, this protection applies exclusively to devices with Apple’s proprietary modem, cannot block E911 emergency location responses, and has no Android equivalent since Google relies on Qualcomm and MediaTek basebands.
The uncomfortable reality persists: cellular protocol architecture designed when networks operated as trusted infrastructure now enables ubiquitous tracking of billions of devices with SIM connectivity, silently answering location queries beyond user control or awareness.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.
