Except in the case that the device will not accept the build without the user's passcode, right?
Bugs will always be found and it’s a mistake to think even the latest iPhone is immune to attack. In particular, the baseband continues to be a large attack surface, and IMO is the vector most likely used by the Saudis to remotely access iPhones on their cellular network.
I’d feel safer if a powered off iPhone did not connect to any network (WiFi, Cell, or USB) after booting until the passcode is entered.