I would assume that any decent spying agency can produce any certificate they want by some CA trusted by Chrome and Firefox and Safari.
And not just NSA / Mossad, by also spying agency of an Estonia, Slovenia and Mexico.
- Or is there reason to expect that is not happening?
- And anyway that is not a good reason to let also known malware companies to do the same.