(A) signing into iCloud (Requires Apple ID Password) + approving the new device on an existing device that has Keychain access
or
(B) signing into iCloud (Requires Apple ID Password) + performing SMS 2FA + entering the device passcode of your primary device
The threat model here is where a nation-state actor enlists the full cooperation of Apple and gets Apple to hand over your encrypted iCloud Keychain, then gets Apple to siphon your Apple ID password next time you sign in. They could then use those two pieces of information to brute force the passcode on your encrypted Keychain data. If you have an 8+ digit passcode, or an alphanumeric passcode, that makes it exponentially harder to brute force.
With the long passcode, your only remaining threat would be Apple shipping malicious hidden code or an RCE in their product that allows them to force your device to approve new devices non-interactively, which would allow them to approve a malicious device the next time you approve your own new device for access to iCloud Keychain.
Or perhaps it's more likely that, when you're setting up a new device, Apple sends over the name of your new device, but with the public key/CSR of their own device, since iOS doesn't show a key fingerprint during device approval or anything.
0: https://support.apple.com/guide/security/secure-icloud-keych...
I remember, a long time ago when i created an AppleID, there was a yes/no choice whether or not to upload [something related to the password] to Apple, so it would become possible to recover the AppleID password if needed in the future.
Is that still a thing, or has it been replaced by new features now?