These researchers took a phone they owned and setup a situation where a server they controlled sent messages the phone interpreted as coming from Apple. Those messages were used to extract the key from the phone they owned. They then used that key to access an account they owned and were the authorized user of.
Is there a technical case of unauthorized access if they used a non Apple client to access the photo? Maybe. Did they establish the same pattern as Weev, accessing information related to many other users? No.