I got very concerned this week after reading and trying it out myself that someone malicious can completely reset and hijack pretty much everything on your phone as well as iCloud account if they see you typing your passcode and then take your phone.
See this article:
non-paywall: https://archive.ph/5TjOQ
Is there anything to do to protect against this? Can this function be deactivated? As it is, I'm thinking of deleting financial apps from my phone that can initiate any kind of money transfer...
XtremePhotoDesign t1_j9zfv79 wrote
Use a separate password for financial apps that is not saved in iCloud Keychain.
Use Face ID or Touch ID.
If you have to enter a passcode in public to unlock your phone, look over your shoulder and hide what you enter.
Use a custom alphanumeric passcode to unlock you phone instead of a 4 or 6 digit PIN: https://support.apple.com/en-us/HT204060