Great writeup there. Looks like a Apple JWT bug and the verification went through despite it being 'signed' and 'tamperproof'. Clearly its footguns allowed this to happen, thus JWTs is the gift that keeps on giving to researchers.
What did I just outline days before? [0]. Just don't use JWTs, there are already secure alternatives available.