We may earn affiliate commissions for the recommended products. Learn more.

What is GPS spoofing? How it works and why people use it


GPS spoofing means making a device or app report a location different from the device’s physical location. This way, apps that use location data (e.g., maps, ride-hailing services, dating apps, games, and social media platforms) may then receive the coordinates you chose (i.e., selected in software), not the coordinates calculated from nearby satellites.

While it might seem close to changing an IP address with a VPN, GPS spoofing is a broader concept. The two affect different kinds of location data and can be used together when an app or website checks both. In this guide, I explain how GPS spoofing works, its legitimate use cases, and walk you through the setup steps.

How GPS spoofing works

Your phone’s location system combines several signals. GPS and other satellite navigation systems determine location by measuring the time it takes radio signals from satellites to reach the device. A receiver commonly uses measurements from at least four satellites to solve its position and correct for its own clock error.

Phones may also use nearby Wi‑Fi networks, cell towers, Bluetooth beacons, motion sensors, and assisted-GPS data to speed up location fixes or improve accuracy. This is particularly applicable indoors or where satellite signals are weak. Notably, Wi-Fi and Bluetooth scanning can contribute to location estimates even when those radios aren’t actively connected to a network or device. This way, a phone with Wi-Fi on but not joined to any network can still be located by the networks it merely detects nearby.

So, how is it different from what a virtual private network (VPN) does? GPS spoofing targets the location data that an app receives from the operating system. A VPN targets a separate signal: it changes the IP address an online service sees, but has no effect on GPS coordinates, since satellite positioning works independently of your internet connection and never passes through the VPN tunnel.

There are two levels at which spoofing can happen:

  • Software-level spoofing. A mock-location tool makes the operating system report false coordinates to compatible apps. The phone may still receive real satellite signals, but apps are given a different location.
  • Signal-level GPS/GNSS spoofing. Counterfeit radio signals can cause a GPS receiver to calculate a false location. Unlike a mock location on one device, this can affect nearby devices and interfere with navigation or emergency systems. However, transmitting such signals may be illegal.

Common GPS spoofing use cases

Software-level GPS spoofing is mainly useful when you need to control the location an app receives without physically traveling there. Common scenarios include:

  • App development and QA testing. Developers can verify that an app shows the right local results, map pins, delivery areas, language prompts, weather data, or location-specific error messages.
  • Privacy from location tracking. Plenty of apps today request location access for reasons unrelated to their core function (e.g., ad targeting, analytics, nearby-friends-type features you never use). Spoofing denies them accurate data, as an alternative to revoking location-tracking permissions outright, which some apps typically won't function without.
  • Testing location-dependent features and workflows. Some services behave differently or aren't available at all outside certain countries. Developers and privacy-conscious users sometimes use location spoofing to check that geofencing logic actually works as intended.

There are also many gray areas I cannot ignore, which include cases like spoofing location in location-based games or getting around a dating app's distance filters. These typically violate the specific app's terms of service, even where the act of spoofing itself isn't illegal, and can get an account banned.

How to spoof location on Android

Android has built-in mock location support in Developer options. The wording and menu path can vary by phone manufacturer and Android version, but the general process is similar:

  1. Install a location-testing or mock-location app from a source you trust, since Android doesn’t have a default one.
  2. Go to your Android device’s Settings, then About phone, and tap Build number 7 times to open Developer options. This step may require you to enter your password or PIN.
  3. Go back to Settings, choose System or Developer options, depending on your Android device.
  4. Look for the Select mock location app and choose the mock location app you installed.
  5. Open that app and set the coordinates or map location you want your device to report.
  6. Go to Google Maps or any other location-based app to confirm it now reflects the mocked position.
  7. To disable location spoofing, stop the mock location and go back to the Select mock location app and set it to None. You can also disable Developer options when you no longer use them.

Note that some apps may still detect and reject mocked coordinates regardless of which tool you use to set them, since Android flags spoofed locations with an isFromMockProvider marker that any app can check. For example, ride-hailing and banking apps in particular tend to look for it.

Set up location spoofing with a VPN on Android

This isn’t exactly an elaborate process, but it’s worth mentioning that some premium VPN apps build GPS override directly into their interfaces, making it a lot more friendlier. Here’s how to set it up with Surfshark's Android app:

  1. Open the Surfshark app, go to Settings > VPN settings, then scroll down to Advanced settings and tap it.
  2. Find the Override GPS location and enable it. This should prompt a pop-up that asks you to adjust device settings before the feature can work. Tap Let's go.
  3. Tap Open settings to open your Android device’s Developer options and find the Select mock location app.
  4. Choose Surfshark from the list of apps.
  5. Once setup completes, tap Close.

What makes this method more convenient for me is that IP and GPS locations move together with a single toggle, which eliminates the need to manage a VPN server and a mock-location app separately.

How to simulate a location on an iPhone

iOS doesn't provide the same user-facing mock-location setting as Android does because Apple restricts this to development tools. This means you can generally only do this for development and testing purposes, and you will need a Mac and Xcode.

On the iOS Simulator (for testing in Xcode), follow these steps:

  1. Run your app in iOS Simulator from Xcode.
  2. In the Simulator menu bar, choose Debug > Location.
  3. Select a preset location or route, or choose Custom Location and enter latitude and longitude coordinates.

On a physical iPhone, here’s what you need to do:

  1. Connect the iPhone to your Mac and run your app from Xcode.
  2. In Xcode, create a GPX file through File > New > File > GPX File. Add a single coordinate for a fixed location or multiple waypoints for a route.
  3. While the app is running, choose Debug > Simulate Location in Xcode and select the GPX file.
  4. When testing is complete, stop the simulation from the same menu or end the Xcode run session.

You may find third-party tools that claim to spoof iOS location without Xcode, but they typically require sideloading or older iOS versions. In practice, though, Apple treats most of them as unsupported and blocks the underlying mechanism in newer releases.

Note:

Neither Android nor iOS perfectly hides mock locations. Android flags mocked coordinates at the API level so any app can check for them, and many financial, rideshare, and dating apps do exactly that. iOS doesn’t offer a similar system-wide mock location setting at all. iOS developers can simulate locations when testing an app in Xcode on a Mac, but this is a development tool rather than a consumer location-spoofing feature. For these reasons, treat GPS spoofing as something that works well for privacy and testing purposes, and unreliably for anything an app has a financial incentive to prevent.

Privacy and troubleshooting tips

If your goal is digital privacy, location spoofing isn’t the only option. Here’s what else you can try:

  • Review permission controls first. Deny location access to apps that do not need it, or choose “Allow while using the app” instead of background access.
  • Use the approximate location when the OS offers it. Many apps only need a rough area to provide local weather, search results, or regional content.
  • Review Wi-Fi and Bluetooth scanning settings. A device may estimate its location from nearby networks and beacons even when it’s not actively connected to them.
  • Check photo metadata before you share images. Photos can include GPS coordinates in EXIF metadata. I recommend turning off location tagging in the camera settings or removing location metadata before publishing.
  • Expect some apps to detect inconsistencies. A false GPS coordinate, paired with Wi-Fi networks, nearby Bluetooth beacons, a cellular region, and an IP address from elsewhere, may cause an app to show an error or request further verification.
  • Never rely on spoofing for safety-critical navigation. It can create dangerous routes, emergency-response, or location-sharing errors.