My understanding is that the support is less about the device OEM and more about the SoC supplier (ie Qualcomm). Once Qualcomm decides they're not supporting the SoC anymore, there's not much the OEM can do in terms of security patching. This is the understanding I've picked up from similar discussions over the years, but I very well may be wrong.