I have to imagine a big part of their sales pitch was, you should definitely put this everywhere and turn on automatic updates because then you'll be the most secure. If it's written down anywhere about how their QA practices prevent exactly this kind of thing happening, then I think there's probably an argument they should be held liable. (This is from an tech perspective, not a legal perspective)
One enabled this, another perpetrated it.