Superfish is not a man in the middle, by definition. It's running on your local computer. That's not the middle. That's the start. Consider that Superfish could have just done binary patching on the browser binaries instead of fiddling the local SSL configuration ... it's put there by the computer manufacturer so they can do anything they like.
Which obviously didn't work here, as Chrome was one of the most affected targets.
Firefox on the other hand, was more or less absent altogether. I know which browser I will trust.