Yep, and if it gets hacked, then all you need to do is change your fingerprints.
Until the next round of FBI tools, where they extract the fingerprints to their database as part of their unlocking process.
This is covered in the Apple Platform Security Guide.
https://manuals.info.apple.com/MANUALS/1000/MA1902/en_US/app... (I believe this link can change when the guide gets updated)
If you do a little bit of reading about the topic, too, note how well-designed biometric systems require more than a simple fingerprint or photograph — e.g. Apple's FaceID has liveness checks for eye motion and uses a 3D scan. None of these are impossible for a well-resourced attacker but that's true of the alternatives as well. This is why you need to think in terms of threat models — e.g. the attacker who can get a high-resolution 3d scan of your face can also watch you type your passcode in so the latter isn't more secure in practice.
If an attacker watched you type in your passcode, what would you do about it?