The problem was introduced via an update to the HTC phones that installed a tool called HTCLogger that collects the data. The tool was apparently meant as a way for developers to get detailed information about what is causing problems on a device. Researchers developed a proof-of-concept app that shows how much data any arbitrary app can access on the affected devices, which include the EVO 4G, EVO3D, Thunderbolt and others. Many Android apps have the android.permission.INTERNET permission by default.
Source: https://threatpost.com/htc-android-phones-leak-private-user-data-100311/75711/

