What is the solution? More security education for general SWEs? It seems like whatever team worked on this feature never considered any security perspectives.
The solution is simple: similar in thought to GDPR, make vendors of proprietary products above a certain size (e.g. market share, net worth, # of employees) liable for security issues even if they do not result in privacy breaches.
Vendors will then either have to release their software as open source or need to carry insurance for security issues, and the insurance companies will only provide insurance if company processes are following industry standards - e.g. code reviews, security audits during concept and development, appropriate staffing of developer teams or requiring certifications/training for developers.