Earlier quoted context omitted.
Isn't it the same with many Linux distros? Updates are using root to run?
It's largely the same for all automatic updating systems that don't protect against personalized updates. I don't know the status of the updating systems of the various distributions; if some use server-delivered scripts run as root, that's potentially a further powerful attack avenue. But I was assuming that the update process itself is safe; the problem is that you usually don't have guarantees that the updates you…
A point of order: you do have that guarantee for most Linux distro packages. All 70,000 of them in Debian's case. And all Linux distro distribute their packages anonymously, so they can never target just one individual.
That's primarily because they aren't trying to make money out of you. Making money requires a billing relationship, and tracking which of your customers own what. Off the back of that governments can demand particular users are targeted with "special" updates. Australia in particular demands commercial providers do that with its "Assistance and Access Bill (2018)" and I'm sure most governments in the OECD have equivalents.