both touchID and faceID are ephemeral and expires after 24 hours (configurable, i think). Unless the device was obtained from the person immediately any hardware hack to bypass them won't work.
It is still a 24h block (let's use the default) where the device is vulnerable. In many countries there are no protections against pressing your finger on the phone, or worse yet, turning it to face you.
It also disables biometric unlocking until the password is entered.