An “interesting” part of this is, up until now these photos had little technical exposure. But now that millions of phones can be affected, creating unrelated pictures that purposefully match these hashes becomes a shinny target.
If someone wanted to generate a false positive image, they could already leverage it on these other platforms.
Google Photos (+ Google Drive I guess ?) is on by default only on Pixel phone I think, and not by default on Samsung phones. For Facebook you have to post the images, for Microsoft I don't think there is any scanning inside Windows itself and by default, I guess it's on OneDrive ? Those companies are big, but the majority of pictures still go through iOS first and foremost.