I would imagine it is not 'ridiculously hackable' with a photograph seeing as it has a dedicated infrared dot projector and dedicated infrared depth sensing camera.
So it may be possible - some techniques have found that creating a 3d model of someones head and then placing photos in the appropriate places can have a good attack vector against Apple's Face-ID. Also some reports that creating a true infrared photograph under certain situations might be a cuase for concern.
However 'ridiculously hackable with a photograph' is not a term that I would use for a 3D IR depth sensing unlock system.