Any webapp that I would consider secure MUST validate all input from clients. This includes white listing any and all parameters names, preferably in middleware, but at least in the controller. Allowing random keys in your input seems recipe for disaster, when you consider a multi layer app security policy. While this may seem like an overkill to some, this is best practice I've seen implemented in any project that deals with real money.
Hence, such a change in iOS WILL break any such application. Irrespective of your views on the sanity of mass assignment.
I would like to see a discussion on why apple thought it would be a good idea to introduce a new parameter to every request. Any ideas?