Browsers and TLS infrastructure have been solving that for a while now, via certificate transparency. Browsers can now reject any certificate that isn't publicly logged. So, yes, they could MITM, and burn an entire CA doing it.
If you're dealing with an authoritarian state they don't need to burn anything or care about cert logging. They can:
1. Make it illegal to distribute a browser that distrusts their CA
2. Make it illegal to run a browser that distrusts their CA
3. Block all encrypted traffic that they can't MITM and notify police that you are running illegal software
If you're dealing with an authoritarian state they don't need to burn anything or care about cert logging. They can: