Sure, and Windows is much the same wrt bundling. The tradeoff is that now you've multiplied the responsibility of library updates across everyone that bundled it. You probably won't care if simple library version updates are missed, if the app itself doesn't care. You might care more about bugs that require every app to update, especially if it's a security bug.
Sure there's a tradeoff, but for most people it's really rare to use software that isn't being actively maintained. So let the maintainers update their dependencies when there's a security flaw, the auto-update will pull in the changes, and I'll still benefit from OS X's 30-second install process.