/Applications is writable by admins. There is no O/S security model to bypass.
So yes, there is some blame to be laid at the OS for running binaries with the privileges the current user has, but it's clear that the installer doesn't behave like a regular installer would.