As a developer on the automatic update platform for a widely-used web browser:
Securing a widely-used software package that connects to arbitrary servers is hard. Not just that eventually every last one of our bugs will be exercised by some web site somewhere, but we’re an obvious high-value target for separately-installed malware.
We have to write a web browser that is itself resilient to malware attacks. If users can shut off automatic updates or malware defense, malware can shut it off...