So I may be missing something here but I was wondering, doesn’t the “forgot password” feature on most websites/ apps cause a huge security issue??

Because let’s say someone stole my phone he has my email address for Instagram He tries logging in and chooses “forgot password” He can easily change my password Then what??

Or even if he somehow hacks into just my email he can still remotely get into any other app using the “forgot my password” feature

Am I right? Or am I just sounding stupid idk