I've heard the same for Windows code signing certs - that's it possible to modify the payload and have the signature still apply.
Dropbox’s installer used it a while ago (maybe still, haven’t checked): https://news.ycombinator.com/item?id=8204454
> These attributes are not part of the signedAttributes which is used to actually authenticate the signature
https://learn.microsoft.com/en-us/archive/blogs/ieinternals/...
> unverified data within the PKCS #7 blob itself which will not be taken into account when verifying the Authenticode signature
Of course software can abuse it by loading code from the unsigned portion, but that requires code in the signed portion to be complicit. In that case the signature still does its job of telling you exactly who was responsible for that fuck-up.