I think you misunderstood the threat model. The concern is that they seized your phone, used the exploit to bypass the "normal" passcode protections, allowing them to bruteforce your 6 digit passcode in hours/days rather than years/decades/never (if you had the wipe after 10 failed attempts enabled).