Google

Android OS 5.1 'Lollipop'

Android OS 5.1 'Lollipop'

The Google Android OS 5.1 'Lollipop' reached end of service life on Mar 1, 2018 — Google no longer ships security patches or fixes for it. Our third-party support keeps it safe to run: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance.

End of Service LifeEOSL Date: Mar 1, 2018
Issue Management

24/7 engineers own your Android OS 5.1 'Lollipop' incidents end to end.

Vulnerability Remediation

Mitigation and patch-around guidance when the vendor no longer ships fixes.

Compliance Maintenance

Controls evidence and documentation that keep auditors satisfied.

Specifications

product
android
release
5.1
product Label
Android OS
release Label
5.1 'Lollipop'
codename
Lollipop
lts
latest Version
release Date
2015-03-01
maintained
source Url
https://endoflife.date/android

Lifecycle Dates

End of Service Life
Mar 1, 2018
Last OEM Support
Mar 1, 2018

Get Third Party Support

Your quote will be sent to this address.

By submitting this form, you agree to our Privacy Policy.

OEM vs. 3rd Party Support

See how third-party support compares to the vendor contract for Android OS 5.1 'Lollipop' — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.

FeatureOEM Support3rd Party Support
Post-EOSL Support
Break/Fix Support
Until EOSL
24/7 Monitoring
Vulnerability Scanning & Remediation
Managed Operations
Procedure & Configuration Review
Compliance & Audit Documentation
Limited
Discounted Migration to Other Platforms

Why Choose 3rd Party Support for Android OS 5.1 'Lollipop'?

Vulnerability Remediation

Scanning, mitigation and patch-around guidance for Android OS 5.1 'Lollipop' when the vendor no longer ships fixes.

Compliance Maintenance

Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.

24/7 Expert Support

Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.

Android OS 5.1 'Lollipop' Support: Frequently Asked Questions

Is the Google Android OS 5.1 'Lollipop' still supported?

Google ended support for the Android OS 5.1 'Lollipop' on Mar 1, 2018 — no more patches or fixes from the vendor. Third-party support keeps it covered: our engineers manage issues, remediate vulnerabilities, and help you maintain compliance for as long as you run it.

When is the Google Android OS 5.1 'Lollipop' end of service life (EOSL) date?

Google lists the end of service life for the Android OS 5.1 'Lollipop' as Mar 1, 2018.

Can I keep using the Android OS 5.1 'Lollipop' after its EOSL date?

Yes. EOSL means Google stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.

How much does third-party support for the Android OS 5.1 'Lollipop' cost?

Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.

Known Vulnerabilities Affecting Android OS 5.1 'Lollipop'

2831 published CVEs affect the Google Android OS 5.1 'Lollipop', including 1958 rated critical or high severity. Google no longer ships security patches for this release — our engineers provide mitigation guidance, workarounds and hardening support.

CVESeverityCVSSPublishedSummary
CVE-2026-0124CRITICAL10.0Mar 10, 2026There is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2025-48611CRITICAL10.0Mar 10, 2026In DeviceId of DeviceId.java, there is a possible desync in persistence due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-47040CRITICAL10.0Dec 18, 2024There is a possible UAF due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-47038CRITICAL10.0Dec 18, 2024In dhd_prot_flowrings_pool_release of dhd_msgbuf.c, there is a possible outcof bounds write due to a missing bounds check. This could lead to localcescalation of privilege with no additional execution privileges needed. Usercinteraction is not needed for exploitation.
CVE-2018-9416CRITICAL10.0Dec 5, 2024In sg_remove_scat of scsi/sg.c, there is a possible memory corruption due to an unusual root cause. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-0126CRITICAL9.8Jun 16, 2026In WC-Radio, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-0120CRITICAL9.8Mar 10, 2026In modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-0116CRITICAL9.8Mar 10, 2026In __mfc_handle_released_buf of mfc_core_isr.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-0114CRITICAL9.8Mar 10, 2026In Modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-0113CRITICAL9.8Mar 10, 2026In ns_GetUserData of ns_SmscbUtilities.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-0111CRITICAL9.8Mar 10, 2026In ns_GetUserData of ns_SmscbUtilities.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-0110CRITICAL9.8Mar 10, 2026In MM_DATA_IND of cn_NrSmMsgHdlrFromMM.cpp, there is a possible EoP due to memory corruption. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2025-36937CRITICAL9.8Dec 11, 2025In AudioDecoder::HandleProduceRequest of audio_decoder.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2025-36904CRITICAL9.8Sep 4, 2025WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396458384.
CVE-2025-36897CRITICAL9.8Sep 4, 2025In unknown of cd_CnMsgCodecUserApi.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2025-36896CRITICAL9.8Sep 4, 2025WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-394765106.
CVE-2025-36890CRITICAL9.8Sep 4, 2025Elevation of Privilege
CVE-2024-53842CRITICAL9.8Jan 3, 2025In cc_SendCcImsInfoIndMsg of cc_MmConManagement.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2018-9388CRITICAL9.8Dec 5, 2024In store_upgrade and store_cmd of drivers/input/touchscreen/stm/ftm4_pdc.c, there are out of bound writes due to missing bounds checks or integer underflows. These could lead to escalation of privilege.
CVE-2024-32913CRITICAL9.8Jun 13, 2024In wl_notify_rx_mgmt_frame of wl_cfg80211.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

Showing the 20 most severe of 2831 known CVEs.

Get Third Party Support

Related Google Products

All Google products →
Android OS 5.1 'Lollipop'
Save 40-70% vs OEM
Get Third Party Support