They have a REST server running locally, and they want to link to it from websites on the internet. So they created the domain localbattle.net which points to 127.0.0.1. But there's a problem, they can't use http traffic (because of mixed content warnings, even though it wouldn't really be insecure), so they have to use https traffic. They can't use a public CA because the CA would throw a fit if they found out keys for certs were being distributed in an application (they could lose trust in major browsers due to something like that). So they generate a non-ca certificate (notice the cert doesn't have basicConstraints: CA=true) during setup, install it in the OS so the browsers trust it, and use it in their local webserver. The key is only available on the computer (and I assume it's stored in a secure manner). The only way they could use this cert to mitm your SSL traffic, or phish/pharm you is to do that same process with a different domain in the subjaltname extension.
I think this is a clever and secure solution to the problem they face. At the end of the day you're already running their code on your computer and have given it admin privileges in the past, so you can't say you don't trust the application, and this doesn't introduce any supply-chain type vulnerabilities that could be exploited down the line (that didn't already exist in the auto-updater, which is a much bigger issue I have with the Blizzard client).
So I guess I'm asking, what am I missing, why is everyone freaking out at Blizzard?