This attack scenario doesn't make any sense. If your phone is out of your sight and unsecured for long enough to take it apart and replace the fingerprint sensor, it's unsecured and out of sight long enough to be entirely replaced by a clone that will steal all your credentials and send everything to whatever bad guy you are imagining
And it won’t work anyway because the phone will detect and reject the sensor and just fall back to PIN authentication which is how it worked before the update