Earlier quoted context omitted.
What about DNS spoofing[1] at the local network level? [1] https://en.wikipedia.org/wiki/DNS_spoofing
The spoofer wouldn’t be able to obtain a valid certificate for the spoofed site, though.
And sadly, a lot of software still doesn't perform certificate pinning.