There are a whole host of controls in place to mitigate this risk. Plus such an acquisition wouldn't be easy to keep secret, so as soon as an untrusted actor acquired control over a root, the CAB would likely immediately distrust the cert.
https://cabforum.org/working-groups/server/baseline-requirem...
CAB has nothing to do with trust/distrust here. Its the Root CA Store Operators (Mozilla, Google, Apple, Microsoft, Adobe) which have to distrust here.