It's not just that they're hard to get - it's also that no one has demonstrated a preimage attack. So given just an illegal hash one can't construct an innocent image with that hash. These demonstrations show only that a second image can be transformed to have the same hash as a first, given image.
As other comments note, that's not a huge increase in difficulty for an adversary willing to deal in actual CSAM.