If that malicious actor can install a custom ca too, they can already install whatever spyware they want.
If that malicious actor can install a custom ca too, they can already install whatever spyware they want.