Who’s liable when a user is tricked into handing over a 2FA code? That’s the vast majority of the incidents I’ve seen over the years.
The software company would argue that the lawbreaking hacker was a supervening cause, while the consumer would argue the criminal was foreseeable. In the case of security software, the consumer might have a point. In practice such a claim is not usually successful.
Customers are already able to insist that software vendors indemnify them for security risks as a condition of purchase. No new laws are needed for this.