This is the duality of automatic updates, on one hand you don't automatically get security updates, on the other, you don't automatically get exploits from new owners or compromised accounts.
In a software project this is really a responsibility I think people don't appreciate that they have, especially in regards to package managers.
But for end user devices it's encouraged to have automatic updates on. I think this is a personal responsibility as no-one really has your back on your device, except the highly automated app store verification. Which in fairness to them, likely stops a lot of exploits/malware making it to user devices.