1.5 Billion Android Devices Vulnerable as OS Support Lapses
Nearly 43% of active Android phones run unsupported operating systems, creating a massive global security gap.
A critical security gap has opened across the global mobile landscape as more than 1.5 billion active Android devices have reached end-of-life (EOL) status. These devices no longer receive essential security updates, leaving a vast portion of the world's smartphone users exposed to known exploits.
Data indicates that approximately 43.3% of active Android phones currently run unsupported operating systems. As of August 2026, only 56.7% of the estimated 3.9 billion global Android devices are running a supported OS, defined as Android 14 or later. This represents a significant downward trend in device health; two years prior, the share of supported devices stood at approximately 65.5%.
The Support Gap
This decline highlights a growing disparity in the mobile market. While smartphone manufacturers prioritize the rollout of generative AI features and extend support windows to five years or more for newest flagship models, a "silent majority" of users rely on aging hardware. This creates a widening divide between the cutting-edge capabilities of new hardware and the actual security posture of the installed user base.
Systemic Risks
These EOL devices serve as active attack surfaces for cybercriminals. Because they no longer receive patches, these phones are susceptible to critical vulnerabilities, including remote code execution (RCE) flaws that can be triggered without user interaction. The danger is further amplified by the rise of generative AI, which attackers use to more efficiently identify and exploit known vulnerabilities in these outdated systems.
Future Outlook
As the percentage of supported devices continues to shrink, the industry faces a systemic risk where billions of users remain permanently vulnerable regardless of the security advancements made in newer OS versions. The primary challenge remains the transition of the global user base away from legacy hardware that can no longer be defended against modern threats. Without a coordinated effort to phase out these legacy systems, the global mobile ecosystem remains fragile, as the sheer volume of unsupported hardware provides a persistent, low-cost entry point for large-scale cyberattacks.