Still working, no longer being fixed
Every Android phone has an end of support date, after which the manufacturer stops shipping the monthly security patches. Nothing visible happens that day. What changes is that newly discovered flaws in the parts of the system only the manufacturer can update stay unfixed. How much that matters depends on what the phone does, and the honest answer is that a phone used for banking and mail deserves a different decision from one used as a music player.
What stops, and what carries on
| Part of the phone | Who updates it | After support ends |
|---|---|---|
| Kernel, drivers, modem firmware | The manufacturer | Frozen, and this is the real risk |
| Android platform security patches | The manufacturer | Stop arriving |
| Google Play system updates | Google, through the Play Store | Often continue for a while |
| Play services and Play Protect | Continue on supported Android versions | |
| The browser and its engine | The browser vendor | Continue until they drop the version |
| Individual apps | Their developers | Continue until minimum version rises |
That split is the useful part. A great deal of what people worry about, the browser most of all, keeps being patched long after the phone itself stops. What cannot be patched is the layer underneath, and that is reached mainly through malicious apps, hostile networks and files, rather than by a phone sitting in a pocket.
Advertisement
The apps that carry the most weight afterwards
The Play Store is also how Play system updates and Play Protect reach the phone. Keeping it current is the single most effective thing on an older device.
Play services updates independently of the manufacturer and carries a large part of the security surface with it.
A browser with its own engine, updated by its vendor rather than the phone maker, which matters when the system WebView is old.
The same argument with tracker and advertisement blocking included, which removes a real slice of the attack surface.
Light, private by default, and a sensible default browser on a phone you are keeping deliberately simple.
Edge. Another independently updated browser, worth knowing about when a site refuses to work in the others.
A password manager matters more on an old phone, because unique passwords limit what a compromise reaches.
Open source two factor codes stored locally with an encrypted export, so moving to a new phone later is not a crisis.
The simpler alternative, with account transfer to a new device when the time comes.
A catalogue of open source apps that often keep supporting older Android versions long after commercial apps stop.
Scans what trackers and permissions the installed apps carry. On a phone you are keeping, knowing what is on it is most of the work.
Puts questionable apps in a work profile, isolated from your main data, and lets you freeze them when not in use.
The same idea with more control, including removing preinstalled apps from your main profile without root.
A tunnel to a network you trust, which is the practical answer to using an unpatched phone on public WiFi.
Shows the exact model, chipset and Android build, which is what you need to look up when support actually ended.
The transfer tool for the day you do replace it. Test it before you need it, not on the evening the new phone arrives.
Carrying on carefully
- Decide what the phone is allowed to do Banking and work mail on a supported device; an unpatched phone is fine for music, maps, photographs and calls.
- Install nothing outside sources you trust Malicious apps are the main route to the parts of the phone that can no longer be fixed. Fewer apps is a real defence.
- Keep the browser and Play services current These continue to update and cover a large part of what a phone is exposed to daily.
- Turn on a lock screen and encryption, and check backups Loss and theft remain more likely than a remote attack, and they are fully in your control.
- Avoid open public WiFi, or tunnel through a VPN An unpatched network stack on an untrusted network is the combination worth avoiding.
- Set a date to reassess A year from the last patch, look again. Support ending is a slope, not a cliff, and the slope gets steeper.
- A second phone for maps and music
- A camera and photo device
- A child's first phone with a small app list
- A phone that never leaves the house
- Banking and payment apps
- Work mail under a device policy
- The only device holding your two factor codes
- A phone several years past its last patch
Giving it a second life
A phone that is no longer trustworthy for your main accounts is still perfectly good hardware. As a dedicated music player, a dashcam, a webcam, a spare satnav or a controller for the lights, it does useful work with no account of consequence signed into it. Factory reset it, sign in with an account created for the purpose rather than your main one, install the two or three apps it needs, and let it get on with that job.
Custom firmware is the other route, and some projects do extend security patches well beyond the manufacturer's date. It is a real option for the technically confident, with real risks: an unlocked bootloader changes the device's security model, banking apps commonly refuse to run, and an interrupted flash can leave the phone unusable. Research the specific model thoroughly before going near it.
Check both update dates, keep the browser and Play services current, take the high value accounts off it, and give the hardware a job that does not need trust.
Frequently asked questions
How do I find out when my phone stopped being supported?
Check the security update date in Settings, then look up your exact model on the manufacturer's support page, which usually publishes the promised years of updates.
Is an unsupported phone dangerous to use?
Not dangerous by itself. The risk rises with what you do on it and what you install, which is why limiting it to low value tasks is the practical compromise.
Do apps stop working when support ends?
Not immediately. Over time developers raise their minimum Android version and apps stop updating, which is usually what makes an old phone feel finished rather than any security concern.
Does a security app make up for missing patches?
No. Nothing installed on top can fix a flaw in the layer underneath. Play Protect and sensible habits help; they are not a substitute for patches.
Read next
Nothing has infected your phone. Something you installed has permission, and the fix is a list in settings.
A phone will happily run a keyboard, a mouse and a memory stick. It will not power a desktop hard drive.
Hard and fast are different things. Almost every game confuses them, and these do not.

