https://github.com/chromium/ct-policy/blob/master/ct_policy....
You may find this useful: http://www.certificate-transparency.org/how-ct-works
Like any other CA, they do have the technical ability to sign arbitrary other certs, so could issue a cert for MITM. As some other comments show, certificate transparency is starting to reduce this risk.
Whether you use any specific CA, like LE, or not, has no security impact.
It's about what your users trust and you don't control that.