I should also add that to just highlight problems with one specific method of 2FA without establishing that it is still more secure than a single factor password, let alone acknowledging that other methods of identification are available, somewhat misses the point of 2FA.
I'm sure it's more complicated than that in reality, but if you have SMS access, you only need to find one weak link in the chain including iCloud/google, email provider, app provider, etc.
You sure can, but will you then have the requisite TOTP secrets?
Good news is according to apple [0], you can protect your icloud keychain with a six digit code required to move the keychain to a new device.
If instead of SMS the 2FA use only a software token generator, then highjacking the cell network would not be a successful attack vector.