It could be edge cases for sure. But it’s a low level attack that can have devastating outcomes. Fact remains, Apple needs to fix these security flaws.I dont know yes or no about resetting the recovery account or password after it’s been set. But my point about these being edge cases out of billions of devices and not the general case. If someone has your phone and password yes it’s a problem, not so much with just the phone.
The same ne’er do well as mentioned above could demand your bank id and password and then it’s the same thing.