Example: if you have an SD card installed, one advertising SDK creates a file on it. When the SDK is running in an app with appropriate permissions, it writes the IMEI and advertising ID to that file. When it's running in an app without appropriate permissions, it retrieves the IMEI and advertising ID from that file.
Lots of interesting tricks. The one that surprises me the most is Unity using ioctl tricks to harvest the device's MAC address.