It's enforceable because any such fraudulent certificate, once found, identifies both the dodgy intermediate CA and the responsible root CA. The fraudulent cert itself provides all the proof that Mozilla needs to revoke the corresponding root.
The fraudulent certificates could be found and saved by a user using Chrome's certificate pinning feature, or Firefox's Certificate Patrol add-on, or similar.
The fraudulent certificates could be found and saved by a user using Chrome's certificate pinning feature, or Firefox's Certificate Patrol add-on, or similar.