They look like they worked hard to cover that, even training the network to reject 3D face models done up by Hollywood makeup artists. It's hard to see how you'd spoof it better than that.
Doesn't really have to look like a hollywood mask though, fooling neural networks is a growing area of research these days: http://www.evolvingai.org/fooling
There are probably many redundancies in face ID, but I wouldn't be surprised if some interesting techniques for fooling it show up.
This is a fundamental issue with developing secure software/tech in a private. You have to hope you are the smartest team in the world and that you thought of everything. It's you vs everyone else.