I think this is a serious concern that needs to be fully addressed. What you described in combination with a denial of service attack could potentially allow someone to take advantage of the ledger due to the lack of settlement finality.
I wrote up these concerns here https://steemit.com/raiblocks/@selfdrivingsandp/raiblocks-lack-of-settlement-finality