Yes, user interaction was required.
The bootloader issue only works if the attacker first lands a successful phishing attack: the user has to be tricked into installing a fake BitBoxApp carrying manipulated firmware, then unlock the device to go through with it. High technical finesse on the attacker side, plus several deliberate steps on the user side.
It was already fixed in July with the Oeschinen release, firmware 9.26.2.
Nova is not affected, the bootloader versions involved are older than it.
The memory corruption issue we fixed now is a different one. It only applies to a Multi edition device with no wallet set up yet, plugged into a malicious host. Bitcoin-only is not affected, that code isn't in its firmware.
β€οΈ1π«1