
Articlesmartphones
What actually happens when your phone stops getting security updates?
Ahmad JAug 16, 2026 min
Nothing happens on the day, which is why this is so easy to ignore. Here is the real sequence: what changes, in what order, why the dangerous part is the one with no signal, and why the thing that finally forces most people to act is a banking app rather than an attack.
First, check that it actually has stopped#
A surprising share of people asking this question have not lost support at all. Three different things get mistaken for it, and only one of them is the end of security updates.
- Your phone cannot install the newest OS version. This is the most common confusion and it is not the end of security updates. Apple patches older iOS releases on security-only branches: on 11 May 2026 it shipped fixes to iPhones going back to 2015, none of which can run the current iOS.
- Your updates arrive less often than they used to. On Samsung this is documented rather than a fault: devices move from a monthly security cycle to a quarterly one as they age. Quarterly is still supported.
- Your patch level is a few months behind on a device that should be current. That is usually your carrier or region rather than the manufacturer, and it is a delay rather than an ending.
The actual ending looks different: the maker says so, or stops listing the device. Google publishes a list of Pixels under a heading stating plainly that those models "no longer receive Android version updates and security updates". (Google's Pixel update policy) Samsung's approach is to publish which devices it is patching now, so a model's absence from both the monthly and quarterly lists is the signal, and Samsung notes the lists change as support periods expire. (Samsung's security update scope)
Note
There is a real early warning available on a Galaxy, and almost nobody uses it. A device does not usually fall off Samsung's lists from a standing start; it moves from monthly to quarterly first. If your phone has made that move, nothing is wrong and nothing needs doing today, but the countdown has visibly begun and you have months or years of notice.
What changes, in the order it changes#
The reason this question gets answered badly is that both popular answers describe a single moment. There is no moment. There is a sequence, and the parts of it that matter arrive long after the part everyone worries about.
The risk arrives with no signal and the inconvenience arrives with a notification. So people act on the inconvenience.
The honest version of the risk#
Here is the part usually either inflated or waved away. An unsupported phone is not infected, is not broadcasting your passwords, and is not going to be broken into tonight because a patch was missed. Most people running an unsupported phone will have no security incident at all, which is why the alarmist framing loses credibility with the audience it is aimed at.
But the structure of the situation genuinely does get worse, and it only moves one way. Every flaw discovered after your last patch stays open on your device for as long as you keep using it. The set of known ways in grows, never shrinks, and you cannot see its size. That is a different thing from a high probability of harm on any given day, and conflating the two is what produces both bad answers.
Pros
- The device keeps working exactly as before, so there is no emergency and no reason to buy in a panic
- You can plan a replacement for a sale, a trade-in offer or a new model launch rather than react
- Most of the accumulated risk is only reachable through things you do, so your habits still matter
- An unsupported phone remains genuinely fine for uses that never touch money or identity: music, navigation, a camera, a hotspot, a child's first device with no accounts on it
Cons
- Every flaw found after the last patch stays open on the device indefinitely
- There is no signal, ever, when that exposure crosses from theoretical to real
- Anything handling money or identity is the sharpest exposure, and that is what most people use a phone for
- Apps may drop the OS version and force the decision on their timetable rather than yours
- Resale and trade-in value falls faster once a device is publicly out of support, so waiting costs money too
Reducing the exposure without buying a phone#
This is the section that tends to be missing, and the omission is not accidental: it does not sell anything. It is also the honest advice for most people arriving here, who are not going to replace a working phone this month whatever a website says. None of this makes an unsupported phone supported. All of it narrows what an open flaw could reach.
Heads-up
One thing not to do: installing an unofficial or custom Android build to keep getting patches. It can work and there are well-run projects, but doing it without knowing exactly what you are installing swaps a known, slow, understood risk for an unknown one, and it usually breaks banking apps outright.
When it is genuinely time to stop using it#
There is no date, so it comes down to what the phone is being asked to do. The line worth drawing is not about age, it is about what an intruder would find. A phone with your bank, your email, your photos and your identity documents on it is a different object from the same handset with a music app and a map on it, and the same missing patch matters very differently in each case.
- The clearest signal is an app you rely on refusing to run, because that publisher has decided the OS version can no longer be defended. It is a judgement made by someone with liability at stake.
- The second is your own use: if the phone is your primary device holding money and identity, the accumulating exposure is pointed at the things you would least like to lose.
- The third is practical rather than about security: a failing battery, a repair quote worth a meaningful fraction of a replacement, or an OS too old for the apps you need.
It is worth knowing that "off the latest OS" is not the signal, whatever the upgrade prompts imply. Apple maintains security-only branches for older iOS releases and patches them alongside the current one, and on 11 May 2026 it shipped four sets of updates on one day, the oldest reaching an iPhone 6s from September 2015. (Apple security releases) A phone can be years past its last feature update and still receiving the fixes that matter.
Find out where your phone actually stands
Our free checker reads the manufacturers' own pages rather than roundups. It tells you whether your model is still being patched, gives you the exact end date where the maker publishes one, and says plainly that no date exists where the maker publishes none, instead of estimating one.
What actually happens when my phone stops getting security updates?
Nothing on the day. The phone works exactly as before and there is no warning. What changes is that flaws found from then on are fixed on other devices and left open on yours, so exposure accumulates with no visible signal. In practice the first thing most people notice is an app, often a banking one, refusing to run on the older OS version, and that can arrive a year or more after the updates stopped.
Is it dangerous to keep using a phone that is no longer supported?
It is a growing risk rather than an immediate danger, and the two get confused constantly. Most people using an unsupported phone will have no incident. The structural problem is that the set of known ways into the device only grows, you cannot see how large it is, and the sharpest exposure is anything handling money or identity.
Will my phone stop working when support ends?
No. Nothing is switched off and no feature is removed. Over a longer period apps may stop supporting the OS version, new apps may refuse to install and some services may not work properly, but that is app publishers making decisions rather than the phone expiring.
My phone cannot install the latest OS. Has support ended?
Not necessarily, and usually not. Apple patches older iOS releases on security-only branches, and on 11 May 2026 it shipped updates to iPhones going back to 2015 that cannot run the current iOS. On Android, check whether the maker still lists the device as receiving security updates rather than assuming the version number answers it.
How do I know if my phone is still getting security updates?
Check the maker's own page rather than the version number. Google publishes which Pixels have ended support by name. Samsung publishes the list of devices it is currently patching, split into monthly and quarterly. Motorola and OnePlus publish a per-model end date because UK regulations require it. Apple publishes which models run the current iOS and, separately, every security update it has shipped.
Can I keep using an unsupported phone safely?
You can reduce what an open flaw could reach, though you cannot make it supported. The step that removes most of the real harm is taking banking, payments and identity off the device. Keeping apps updated still works after OS updates stop, two-factor authentication elsewhere means a compromised phone is not a compromised account, and installing less narrows the surface.
Should I install a custom Android build to keep getting updates?
Only if you know exactly what you are installing. There are well-run projects, but doing this casually trades a known and slow risk for an unknown one, and it commonly breaks banking apps because they check whether the system is stock.
Why did nobody tell me my phone stopped getting updates?
Because nothing generates a notification for it. Makers publish the information on support pages rather than pushing it to the device, so the end of support is an event you have to go and look up. That is the single biggest reason this catches people out.
Sources
- Google: Learn when you'll get software updates on Google Pixel phonessupport.google.com
- Samsung: Security Updates: Scopesecurity.samsungmobile.com
- Apple: Apple security releasessupport.apple.com



Discussion