Apart from the common decency that the extra install option should be disabled by default:
Isn’t it really bad (and even border-line illegal) to push a new product due to security updates?
In a way, you can see how the marketing/sales guys at Oracle love Java Security Vulnerabilities. It gives them the ability to upsell more ‘Ask Toolbars’ to one of those 3 Billion users!