Yeah, you can spoof it if you have the original hash of the CSAM file and generate a photo that matches that hash, but even then, the photo is scanned again by a different perceptual hash on Apple's own server to rule out a false positive. If the image doesn't have the same visual look to it, it's not going to be sent to human review. I think it's good that this safeguard is in place.
Someone somewhere is going to find some really bad CSAM images and try to create normal looking "fakes" and sprinkle them around on the internet I'm sure, but the images would have to "look" nearly identical to a CSAM image in order to get flagged for human review.
https://www.apple.com/child-safety/...del_Review_of_Apple_Child_Safety_Features.pdf Outlined here