If someone does that you’ve already been pwned. In reality you limit the CA to be domain scoped. I don’t know why domain-scoped CAs aren’t a thing.
Then why use encryption at all when your threat model for encrypted communication can't handle a malicious actor on the network?
(Though getting the browser to just assume http to local domains is secure like it already does for http://localhost would solve that)