certificate transparency only does anything for participating CAs, there are dozens/hundreds of CAs that do not participate in certificate transparency, including several either controlled by the Chinese government, or at less than arms length from its influence.
They can freely sign anything that isn't either certificate pinned, or has a CAA record. And both those things are client dependent, pretty much any ssl client besides chrome or firefox will not have the capability to do either.
They can freely sign anything that isn't either certificate pinned, or has a CAA record. And both those things are client dependent, pretty much any ssl client besides chrome or firefox will not have the capability to do either.