We've all made stupid mistakes and not paid a price as high as this!
Your customer data is your customers' data. It's not yours to toy with as you please.
That's the European point of view. In the US, customer data is nothing more than an asset.
Does not help. The cases I saw in the past were people putting Werkzeug's stuff behind ngrok, proxies, nginx in which cases it will all look like local requests.
Aside of that, you cannot securely detect this because what it actually does is passing in a header which if not reliably set can be forged.
It's not exactly uncommon that people leak errors, remote code execution is another level though. It doesn't hurt to be careful with such a feature.
It's still only a way to prevent greater damage, you should still not run the debugger enabled in prod.