Ok, so a malicious person can reset your Apple ID password if they spy your passcode.
So, why are you able to reset your Apple ID password using just your passcode? Probably because people don’t take responsibility with their passwords, often forget them, don’t use iCloud Keychain or some other password keeper, and complain that they can’t access their iCloud account. So, we have an easy-in way to reset your passcode to reset. But that means if someone watched you enter your passcode…they can compromise your account.
And people continue to complain.
Interestingly, many people are fearful of Face ID and Touch ID, so they solely use a passcode instead, making the passcode visible repeatedly during the day. It’s much more likely that someone can spy your passcode than it is that they can fool Face ID or Touch ID.
Is it too much to ask that Apple device users remember the ONE password that allows them easy access to all the other saved in iCloud…their Apple ID password? And to be able to answer security questions if they need to reset it?