The end was the most significant part. They can take over your icloud account with the phone password.
I don't care much about the phone backups on some secondary devices. I do care whether those devices can hijack my icloud account with just that phone's pin.
That seems terribly broken, to be able to change icloud without having the password or without 2FA.
I agree. The first part about the backup seems like a side show because once an attacker has logged into the device they already have access to everything that would be in a device backup (usually).
The attacker with physical access to the phone does not have direct access to the data, only to UI of applications that use that data, which is often something significantly different.
I don't care much about the phone backups on some secondary devices. I do care whether those devices can hijack my icloud account with just that phone's pin.
That seems terribly broken, to be able to change icloud without having the password or without 2FA.