The crux of the issue is that the verification only tells you if the barcode is valid. However, there are no strong relationships between the barcode and the rest of the visual content (photo, numbers, dates, etc). Therefore, one can overlay malicious data around the barcode.
The fix would be to allow the verifier to independently retrieve the license details after scanning the barcode, instead of just seeing a valid/invalid message.