Apple could easily fix this by requiring the user to enter their old password to change their password. You know, like we’ve been doing on the internet forever. https://www.wsj.com/articles/apple-iphone-security-theft-passcode-data-privacya-basic-iphone-feature-helps-criminals-steal-your-digital-life-cbf14b1a
A Basic iPhone Feature Helps Criminals Steal Your Entire Digital Life

The passcode that unlocks your phone can give thieves access to your money and data; ‘it’s like a treasure box’

WSJ