I don't think it would be very difficult for the Chinese government to demand a compromised root cert authority be installed on every device sold there.
They certainly can try, but major vendor will resist. Kazakhstan government has tried this method[1]. They sure can try sneaky ways, but any imported laptop connecting to hotel Wi-Fi could reveal it. [1]: https://blog.mozilla.org/security/2019/08/21/protecting-our-...
It's China. Apple/Microsoft isn't going to resist. Google might not resist because they're already banned there so they've got nothing to lose. Regardless, it doesn't really matter because there's a bunch of homegrown chromium forks that can readily replace Chrome.