Lollypop said:If done the right way I dont see how it could be a problem. For one, the user has to explicitly add the 3rd party product, apple could also act as a intermediary or something, the update will only become available through software update once apple has tested it (can download it youself when released), and even though the update comes from the 3rd parties webserver the hash is stored on apples servers and the update HAS to be verified and compared to the hash.
edit: spelling
Or distribute from Apple's servers like the OS updates and the problem disappears, no more security problems than if you were going for OS updates.....