How could a browser protect itself from being "infected" from the underlying OS layer? Given that the malicious installer has administrative access, it's a hole new set of challenges if they can't trust their own filesystem.
It sucks, and nobody is happy with it, but at the end of the day it's the only thing that seems to be working.
It's terrifying. And while you could make a case for this "not being chrome's problem", the fact is that it's really hurting their user base, so they can't not do something about it.