Security affects everyone. Even if I can keep my own machine uninfected, I can't do the same for my bank's machines. Nor can I do the same for random strangers whose machines get 0wned and then used to launch new attacks against me, my bank, and everyone else. Insecure software needs to be replaced by more secure software, not put on indefinite life support.
Only thing you can argue is that if someone is using old out of date software they would be at risk, but they are already at risk. Open sourcing Flash would not make it any less secure if it's not being used anywhere anymore.
Why even bother worrying about Chromium? People who are going to want the legacy Flash stuff are running Windows and there isn't even Windows build of Chromium. How come people on HN always come up with some ridiculous edge case that has zero baring on reality.