Electrum does validate block headers but it doesn't handle re-orgs correctly. It just assumes the longest chain has the most PoW in it which is wrong and makes it vulnerable to attacks by malicious Electrum servers.
Block headers do not contain the cumulative work that has gone into the chain (only the difficulty of the current block). A chain's total work must be calculated and stored locally by clients.
https://github.com/spesmilo/electrum/blob/master/lib/blockch...
They don't verify the has in the header is the hash of the previous block's header? They don't that the hash is sufficiently small? They don't calculate the difficulty correctly?
Yes. It's possible to create a long chain at low difficulty and the original bitcoin client protects against that by computing the total "work" that has gone in a chain. However, Electrum just assumes that the longest chain will be the one which has most "work" in it which is wrong.
One could run a modified Electrum server that sends a long chain at low difficulty and double spend Electrum users.