How will this be enforced? If Mozilla or Google added some hard coded certificate into a new browser version, what if a distribution like Debian patched it out? Or if a user can delete it from the certificate stores themselves?
If Debian patches this out, you won't be able to access those sites. That's a living edge case for them.