Which is a fairly high hurdle for an attacker in most instances.
With software projects training people that curl <link to their install script> | bash is totally fine and the insane amount of supply chain attacks lately it's a critical bug that's just begging to be exploited on single user systems.
So yes, patch your systems and definitely do not downplay this.