Realistically most users?
It's already quite a technical barrier to run Arch Linux, and the knowledge to further know about/understand PKGBUILD can only comes with time and is yet another layer filtering people's ability to know how to even try to catch something malicious.
Now consider the layer of even experienced user that's in a bit of rush and doesn't have time to review the full diffs they're upgrading to.
Ralistically it's nearly statistically impossible that 100% of users would be able to all catch and block a given exploit themselves. A shared responsibility model of security [1] comes to mind, and while it's great for users to be active participants in their security, their action/awareness should be a last resort. I wouldn't blame the user.
[1] https://docs.cloud.google.com/architecture/framework/securit...