Because as with traditional HTTPS caching schemes like Squid, it first requires you to first install a Certificate Authority's public key into your application, browser, or OS's Certificate Store, which (barring an already compromised system) an attacker presumably can't just.. do.
FWIW, I learned that first-hand configuring Squid when I used to run my own BSD routers and have seen the situation talked to death online in any thread that mentions OpnSense or a PiHole; no degree is necessary for exposure. We all have our blind-spots, and what matters is a willingness to be in over your head while you do the hard work of learning your way around.
This includes stumbling in the dark until you learn how you learn in the first place.