As long as you know how to edit metadata, you can definitely fool minor “trust systems” like adjusters, police, etc. It’s a big gap. (For any future readers, no I have not done this and would never do it, really.)
The only solution I see is some kind of hardware-linked signature showing that the image was produced at a certain time, by a certain device. In theory, you could make this signature somewhat “provable” and anchored to a specific time by combining something like 1) the latest Bitcoin block hash, and 2) a blockchain anchor, thereby proving that the photo was taken within a certain time widow after the hash was known and before the anchor was published. But even that arrangement is highly susceptible to hardware attacks.
I'd like to be able to use my hardware security key for this purpose (the hardware-linked signature)