This is a HUGE iOS security issue. Especially the last 2 years where you'd be asked for the PIN code when wearing a mask. You're not protected from this, even with 2-factor enabled.

https://www.wsj.com/articles/apple-iphone-security-theft-passcode-data-privacya-basic-iphone-feature-helps-criminals-steal-your-digital-life-cbf14b1a?st=i7u41zn623p8501&reflink=desktopwebshare_permalink

A Basic iPhone Feature Helps Criminals Steal Your Entire Digital Life

The passcode that unlocks your phone can give thieves access to your money and data; ‘it’s like a treasure box’

WSJ
@KrauseFx it’s not
a “Huge” issue, and it also affects Android (but of course articles about Apple always sell better).
It’s the same trick people use to “shoulder surf” whilst you type your PIN at an ATM.
There is no good solution other than users being vigilant when entering their passcode.
@mluisbrown so why doesn’t apple ask for the current password when changing the Apple ID password when the phone was unlocked using just a pin?