This isn't a bug / complaint / observation of a vulnerability of End-to-End per se, you could argue Microsoft could be NSL'd to do the same to a user's operating system.
To counter this you'd need a secure, distributed way to release updates in Chrome. I don't think that's quite in scope of what this project is trying to accomplish.