It's the type of thing that's been done before.
So all a hacker has to do is [1] break into Sony's update servers, [2] create a signed hacked boot loader that automatically [3] starts a MiTM attack on home users?
Yup. Sony appears to be saying that 1 has happened with malicious intent. I believe 2 has been done by console hackers with not-necessarily-evil intent, at least as a proof-of-concept. 3 exists as portable C code.
Alternatively, the bad guys might just want to use their PS3s as the world's largest DDoS platform.
*Wouldn't it be easier to break into Google servers and install a malicious Chrome update?
I doubt it, Google's security is usually pretty good. Even still, that's something that would probably be easier to uninstall.
I wrote a blog post about this with more info at http://extendedsubset.com/?p=47