Simply stealing your phone isn't enough. They also need to know your password change 2-step settings.
So you also need to make sure that your phone's browser doesn't have your Google password stored, and/or your phone's storage is encrypted with a strong-enough key.
Google has made me re-enter my password when modifying 2fa settings.
Sure, but if it's saved in the browser than it can be extracted from the browser
Last I checked, this was not the case- And a major cause for concern.
Everytime I go to https://www.google.com/settings/security and click on 2-step verification, I'm required to enter my password if I haven't done so in the last 5 min or so.
With this scheme someone can't access your account by stealing your phone. You also can't access your account by getting your phone number to point to your new phone though.
Put a strong password on the phone. Not just a PIN. Touch ID makes that practical now.
If you have a targeted attacker then Touch ID is actually less secure.