Why is it any more dangerous than a conventional update, which also needs to be propagated?
If someone were to exploit a running Erlang process, the description of this feature sounds to me like they would have access to code paths that allow pushing new code to other Erlang processes on cooperating nodes.