If you think about it, keeping them offline is a huge security improvement even without the risk of bricking update, so in ways an automated update regime that convinces you to keep your device offline is giving you peace of mind. In a way.
If it allows anyone to remotely execute arbitrary code on a device without the user's consent, it's called an RCE vulnerability. About as serous as software vulnerabilities go, needs to be patched yesterday.
But if it only allows the manufacturer to remotely execute arbitrary code on a device without the user's consent, it's called an automatic software update mechanism and most people somehow consider that it's totally fine.
Automated updates were supposed to give us peace of mind instead of having us worried about what bug or enshittification will follow.
I’d wager that, for most Internet-connected appliances, keeping them offline or disabling autoupdates have way more pros than cons.