It claims to do so by having a willing user install it and grant any permissions it asks for, not really impressive.
On iOS it's having you disable 2 factor auth and letting it into your iCloud account, which
a) relies on you having access to the same iCloud account as the target and
b) gives them access to your data and weakens your account in what is probably the intended use case, shared accounts