Even if they did that, unless the law required MANDATORY returns, it wouldn't impact them much. Go tell your friends their Roomba is a security risk, watch them look at you funny and not care. If someone they knew had their Roomba compromised and it took pictures of them coming out of the shower (hey Roomba, what are you doing in the bathroom?) they'd have a different view but these attacks are too theoretical to care about.

Very few would bother to return their Roomba for replacement, so Roomba still wouldn't have much incentive to invest in security. Though it sounds like they wouldn't have to actually return them, based on the security alert it sounds like the Roomba in question supports wifi. If so it should be able to receive software updates from home base, right?

