The browser implements a new partition in its certificate database for trusted proxy certificates. When talking to in-path intermediaries that present one of these certificates, the browser has the behavior shown. Protocol details are not specified but have elements of the Mcgrew proposal.
Importing trusted proxy certificate files is identical to importing root certificates. And therefore enabling trusted proxy functionality in the browser creates no new vulnerabilities to MITM attacks than are already present in mainstream browsers.