PhoneLifespan
Buying basics

Security Patches vs OS Upgrades: Which One Actually Keeps You Safe?

Brands love to brag about Android version numbers. The clock that actually protects you is the quieter one underneath.

By Muhammad Tahir · Updated September 9, 2026 · 6 min read

When a phone brand boasts about updates, it usually leads with a big Android version number: “four OS upgrades!” But there are actually two different update promises hiding in every support policy, and they do completely different jobs. One decides whether your phone stays safe. The other decides whether it stays new. Confusing them is the most common mistake people make when shopping on support — so let's pull them apart.

OS upgrades: the new features

An OS upgrade is a jump to the next major version of the operating system — Android 16 to Android 17, or iOS 18 to iOS 19. These are the updates with names and launch events. They bring redesigned interfaces, new features, new emoji, and changes to how apps are allowed to behave. When a brand promises “four OS upgrades,” it's promising four of these jumps.

OS upgrades are nice to have. They keep your phone feeling current and occasionally unlock genuinely useful capabilities. But — and this is the key point — a missed OS upgrade does not make your phone unsafe. It just makes it feel a version behind.

Security patches: the lock that keeps getting re-cut

A security patch is the unglamorous monthly update that fixes newly discovered vulnerabilities — the holes that, left open, let malware, thieves, and snoops into your phone. There's no launch event for these. They arrive quietly, often as a “security update” with a date rather than a version name.

This is the clock that actually matters. As we explain in why software updates matter more than specs, the day your security patches stop is the day your phone's real expiry date arrives — even if it keeps running for years afterward. Everything in our what-happens-when-updates-stop timeline is driven by the security clock running out, not the OS one.

Why the two numbers are often different

Here's where it gets practical. Most brands give a longersecurity window than OS-upgrade window. A phone might get, say, four Android version jumps but six or seven years of security patches. That's deliberate and sensible: after the last OS upgrade, the manufacturer keeps shipping security fixes to the version you're on, so the phone stays safe even though it stops getting newer.

You can see this split right across the market in our brand update policies. Asus, for example, pairs a short two-OS-upgrade promise on its ROG flagships with up to five years of security patches. Apple publishes no upgrade count at all and is judged almost entirely on its security-support track record. The lesson: a phone with fewer OS upgrades but a long security window can easily be the safer long-term buy.

So which number should you shop on?

Shop on the security window. It's the number that determines how many years the phone is genuinely safe to use for banking, email, and the passwords that protect everything else. Treat OS upgrades as a bonus that keeps the experience fresh, not as the headline.

That's exactly how this site rates phones: our Safe-to-Buy badges and longest-supported rankingare built around the security end-of-support date, because that's the one that decides a phone's real lifespan. When you compare two phones, line up their security windows first — then, and only then, let the OS-upgrade count break a tie.

Want the full picture of who promises what? Our 2026 brand update-policy comparison lays out both numbers for every major brand — and shows why the headline figure depends on the exact model, not the logo.

How to read a manufacturer's promise

Brands describe their commitments in ways that are technically accurate and easy to misread. A few patterns worth recognising.

“Up to” is doing a lot of work.A promise of “up to four OS upgrades” sometimes means the flagship gets four and the model you are looking at gets two. Check the commitment for the specific device, not the range for the family.

The clock usually starts at launch, not at purchase. If a phone launched eighteen months ago with a five-year promise, you are buying three and a half years, not five. This is the single most common way people overestimate what they are getting, and it is why every support date on this site is an absolute date rather than a duration.

Patch frequency is not part of the promise.Two phones can both be “in support” while one receives monthly patches and the other receives them quarterly. Quarterly cadence means a vulnerability disclosed in January might not be fixed on your phone until April. Google and Samsung flagships are typically monthly; mid-range and budget devices are frequently quarterly.

What actually happens when a patch lands

Google publishes an Android Security Bulletin each month listing the vulnerabilities fixed that cycle, with severity ratings and the affected components. Manufacturers take those fixes, merge them into their own Android builds, test against their hardware, and ship. This is why patches arrive later on some phones than others — the delay is manufacturer integration, not Google.

The patch level shown in your phone's settings is the date of the Google bulletin it incorporates, not the date the update was installed. A phone showing a security patch level three months old is three months behind on published fixes, even if it downloaded something last week. That figure is the most honest indicator of how well your phone is actually being maintained.

Why this changes what you should buy

Once you separate the two numbers, a lot of purchasing advice inverts. A phone with three OS upgrades and six years of security patches is a better long-term buy than one with four upgrades and four years of patches, even though the first number looks worse. You will spend the last two years on an older Android version, which costs you features — but you will be safe, and being safe is the part that determines whether the phone is usable at all.

This is why every figure on this site is built from the security window rather than the OS one. If you want to see how the brands actually compare on both, our brand update policy guide lays them out side by side.

What a security patch is actually fixing

Android security bulletins are published monthly and list specific, numbered vulnerabilities — each one a CVE, a publicly catalogued flaw with a severity rating. A patch level of, say, March 2026 means your phone carries fixes for everything disclosed up to that bulletin, and nothing after it.

This is why an unpatched phone gets progressively more exposed rather than suddenly dangerous. Each monthly bulletin publishes the details of flaws that are now fixed on current devices and permanently unfixed on yours, and those details are public by design so that defenders can act on them. The practical consequence is that the risk on an unsupported phone compounds: after a year without patches it is carrying a year of publicly documented, unpatched holes, and the information needed to exploit them is freely available.

Google Play System updates: the third channel most people miss

There is a component that sits between the two numbers, and it materially changes what an ageing Android phone can still do safely. Since Android 10, Google has delivered a subset of system components — media handling, Bluetooth, network stack pieces and more — through Google Play System updates, which arrive via the Play Store rather than from the phone's manufacturer.

This matters because it continues on some devices after the manufacturer's own patches have stopped, and it covers several of the components historically most exploited. It is genuinely useful, and it is not a substitute for full security patches: it does not cover the kernel, the device drivers, or the manufacturer's own software layer, which is where a great many vulnerabilities live. Treat it as partial cover that softens the cliff rather than removing it. You can check it under Settings, then Security, then Google Play system update.

Monthly, quarterly, biannual: cadence is the hidden number

A phone can be entirely “in support” while receiving patches only four times a year, and manufacturers rarely advertise which cadence a given model is on. Samsung publishes this openly, listing which devices are monthly, quarterly and biannual, and phones move down that ladder as they age rather than stopping abruptly.

The gap this creates is real. On a quarterly device, a critical flaw disclosed in January may not reach you until April, and you are exposed for that entire window even though the phone is nominally supported. Flagships from Google and Samsung are typically monthly for most of their lives; the majority of mid-range and budget devices across every brand are quarterly from early on. When comparing two phones with the same stated window, cadence is a legitimate tiebreaker — and a device dropping from monthly to quarterly is a useful early signal that it is entering the back half of its supported life.

Why manufacturers advertise the number that flatters them

When a brand announces support, it chooses which of the two figures to lead with, and the choice is rarely accidental. A manufacturer offering two OS upgrades and five years of patches will lead with the five. One offering five upgrades and five years of patches will lead with the upgrades. Both headlines sound like “five years” to a shopper, and they describe quite different products.

The asymmetry matters because the two numbers cost the manufacturer very different amounts. Shipping a new Android version means re-testing the entire custom interface layer, every preinstalled app and every carrier integration — expensive, and the reason budget phones get so few. Backporting a security fix to an existing version is far cheaper, which is why long patch windows have spread down the price range much faster than long upgrade commitments.

For a buyer this is good news, because the cheap number is the one that actually protects you. A phone with two upgrades and six years of patches is a perfectly sensible purchase; it will be running visibly older Android by year four, and it will still be safe to bank on. Read the security figure first, treat the upgrade count as a comfort feature, and be suspicious of any announcement that mentions only one of them.

The one-line summary

Security patches decide how long a phone is safe; OS upgrades decide how modern it feels. If you only have room for one number in your head when comparing two phones, make it the security window, and make sure you are counting it from the phone's release date rather than from the day you buy. A phone running three-year-old Android with current patches is a perfectly sound daily device; a phone on the newest Android whose patches stopped a year ago is not, however new the interface looks. Every phone on this site records both figures separately, with the source document linked, precisely so the distinction stays visible — see the longest-supported ranking to compare them directly.

Keep reading

Put it into practice

Check any phone's real expiry date, or see which phones are still safe to buy right now.