If your assumption could indeed happen then it's not a matter of sending an untrustworthy clock signal via the TAN to the chip...it would mean that the entire ETS technology "is for the birds", for the ETS is all about the TAN...
The localclock integrity check is just another encrypted bit stream passing from TAN server to Embassy client. Why should it be any less secure than any other? (duh?)