It does at least look like their docs for the equivalent policy are not vulnerable to this attack though
https://supabase.com/docs/guides/database/postgres/row-level...
ie: The "Update Policies" DSL ensures that the user does not change the user id of a row