This isn't the first time Facebook have attempted this behavior, previously they were successful in purchasing a zero-day exploit and launching it against users. [1]
You may think that case warrants an exception, but it sets a clear precedent and encourages the hoarding of zero-days.
I think it's extremely easy to believe Facebook would launch exploits at users because they already have.
[1] https://nakedsecurity.sophos.com/2020/06/12/facebook-paid-fo...