Articles · Guides

Still working, no longer being fixed

Every Android phone has an end of support date, after which the manufacturer stops shipping the monthly security patches. Nothing visible happens that day. What changes is that newly discovered flaws in the parts of the system only the manufacturer can update stay unfixed. How much that matters depends on what the phone does, and the honest answer is that a phone used for banking and mail deserves a different decision from one used as a music player.

What stops, and what carries on

Part of the phoneWho updates itAfter support ends
Kernel, drivers, modem firmwareThe manufacturerFrozen, and this is the real risk
Android platform security patchesThe manufacturerStop arriving
Google Play system updatesGoogle, through the Play StoreOften continue for a while
Play services and Play ProtectGoogleContinue on supported Android versions
The browser and its engineThe browser vendorContinue until they drop the version
Individual appsTheir developersContinue until minimum version rises

That split is the useful part. A great deal of what people worry about, the browser most of all, keeps being patched long after the phone itself stops. What cannot be patched is the layer underneath, and that is reached mainly through malicious apps, hostile networks and files, rather than by a phone sitting in a pocket.

Advertisement

The apps that carry the most weight afterwards

1

Google Play Store

Google LLC
5.0 5 B+ 104 MB

The Play Store is also how Play system updates and Play Protect reach the phone. Keeping it current is the single most effective thing on an older device.

2

Google Play services

Google LLC
4.3 10 B+ 308 MB

Play services updates independently of the manufacturer and carries a large part of the security surface with it.

3

Firefox

Mozilla
4.6 500 M+ 596 MB

A browser with its own engine, updated by its vendor rather than the phone maker, which matters when the system WebView is old.

4

Brave Browser

Brave Software
4.8 100 M+ 169 MB

The same argument with tracker and advertisement blocking included, which removes a real slice of the attack surface.

5

DuckDuckGo

DuckDuckGo
4.7 50 M+ 83 MB

Light, private by default, and a sensible default browser on a phone you are keeping deliberately simple.

6

Microsoft Edge

Microsoft Corporation
4.7 100 M+ 345 MB

Edge. Another independently updated browser, worth knowing about when a site refuses to work in the others.

7

Bitwarden Password Manager

Bitwarden Inc.
4.7 5 M+ 127 MB

A password manager matters more on an old phone, because unique passwords limit what a compromise reaches.

8

Aegis Authenticator - 2FA App

Beem Development
4.8 500 K+ 7 MB

Open source two factor codes stored locally with an encrypted export, so moving to a new phone later is not a crisis.

9

Google Authenticator

Google LLC
3.9 100 M+ 6 MB

The simpler alternative, with account transfer to a new device when the time comes.

10

F-Droid

F-Droid
4.0 100+ 12 MB

A catalogue of open source apps that often keep supporting older Android versions long after commercial apps stop.

11

Exodus

Exodus Privacy
4.3 100 K+ 7 MB

Scans what trackers and permissions the installed apps carry. On a phone you are keeping, knowing what is on it is most of the work.

12

Shelter

Paper Airplane Dev Team
3.5 100 K+ 2 MB

Puts questionable apps in a work profile, isolated from your main data, and lets you freeze them when not in use.

13

Island

Oasis Feng
10 M+ 3 MB

The same idea with more control, including removing preinstalled apps from your main profile without root.

14

WireGuard

WireGuard Development Team
4.6 10 M+ 7 MB

A tunnel to a network you trust, which is the practical answer to using an unpatched phone on public WiFi.

15

CPU-Z

CPUID
3.2 100 M+ 5 MB

Shows the exact model, chipset and Android build, which is what you need to look up when support actually ended.

16

Data Transfer Tool

Google LLC
3.6 1+ 11 MB

The transfer tool for the day you do replace it. Test it before you need it, not on the evening the new phone arrives.

Carrying on carefully

  1. Decide what the phone is allowed to do Banking and work mail on a supported device; an unpatched phone is fine for music, maps, photographs and calls.
  2. Install nothing outside sources you trust Malicious apps are the main route to the parts of the phone that can no longer be fixed. Fewer apps is a real defence.
  3. Keep the browser and Play services current These continue to update and cover a large part of what a phone is exposed to daily.
  4. Turn on a lock screen and encryption, and check backups Loss and theft remain more likely than a remote attack, and they are fully in your control.
  5. Avoid open public WiFi, or tunnel through a VPN An unpatched network stack on an untrusted network is the combination worth avoiding.
  6. Set a date to reassess A year from the last patch, look again. Support ending is a slope, not a cliff, and the slope gets steeper.
Reasonable to keep using
  • A second phone for maps and music
  • A camera and photo device
  • A child's first phone with a small app list
  • A phone that never leaves the house
Time to move it on
  • Banking and payment apps
  • Work mail under a device policy
  • The only device holding your two factor codes
  • A phone several years past its last patch

Giving it a second life

A phone that is no longer trustworthy for your main accounts is still perfectly good hardware. As a dedicated music player, a dashcam, a webcam, a spare satnav or a controller for the lights, it does useful work with no account of consequence signed into it. Factory reset it, sign in with an account created for the purpose rather than your main one, install the two or three apps it needs, and let it get on with that job.

Custom firmware is the other route, and some projects do extend security patches well beyond the manufacturer's date. It is a real option for the technically confident, with real risks: an unlocked bootloader changes the device's security model, banking apps commonly refuse to run, and an interrupted flash can leave the phone unusable. Research the specific model thoroughly before going near it.

Check both update dates, keep the browser and Play services current, take the high value accounts off it, and give the hardware a job that does not need trust.

Frequently asked questions

How do I find out when my phone stopped being supported?

Check the security update date in Settings, then look up your exact model on the manufacturer's support page, which usually publishes the promised years of updates.

Is an unsupported phone dangerous to use?

Not dangerous by itself. The risk rises with what you do on it and what you install, which is why limiting it to low value tasks is the practical compromise.

Do apps stop working when support ends?

Not immediately. Over time developers raise their minimum Android version and apps stop updating, which is usually what makes an old phone feel finished rather than any security concern.

Does a security app make up for missing patches?

No. Nothing installed on top can fix a flaw in the layer underneath. Play Protect and sensible habits help; they are not a substitute for patches.

Read next

Three different problems with one symptom

Nothing has infected your phone. Something you installed has permission, and the fix is a list in settings.

The port does more than charging

A phone will happily run a keyboard, a mouse and a memory stick. It will not power a desktop hard drive.

Difficult, and never in a hurry

Hard and fast are different things. Almost every game confuses them, and these do not.