Which authentication? My password manager authentication? My email authentication? My apple device authentication?
Apple’s authentication of those factors, or a separate entry point. It is not certainly not unheard of to leave gaping security holes, sometimes ones which bypass multiple security measures (why the downvote?).
Like no rate limiting of the FindMyiPhone API, lol
Then they would have access to my iTunes account anyway...
But then they can easily exfiltrate, which would allow it to happen programmatically and in mass.