This really is a mode designed for those who really desperately need it, and it really is implemented in a strong enough way to be useful (hardware root of trust, no-drive by changes since it requires a reboot with a wiped key bag cache so you must reauthenticate in order to change it). But all of that for consumer-attainable pricing. It doesn't have to be perfect and I'm sure in due time there will be jailbreak-esque attacks. But until then, this is effectively a very high barrier for an attacker that lacks the resources of a nation state (or a smart but bored teenager in a basement these days).
No protection is perfect, and this kind of things are always another layer in a defence-in-depth approach. Just like car locks, the idea is that it becomes enough of a hurdle that someone on a fishing expedition will go look elsewhere. Of course it won't be enough for a determined state actor.
Got any info/links explaining that? Having only read Apple's webpage, it sounds to me like the major problem is slowed down javascript execution? I certainly didn't;t get the impression it's going to shut down all social media apps/websites?
What this seems to be focused on are the "remote zero-click/one-click" vulnerabilities we've seen, in which either a message is delivered that never shows up but installs a backdoor hook, or a website can deliver a malware package to a particular user and install the backdoor hook without notifications.
It sounds like it does improve some of the physical security features, which should help reduce attack surface, but I wouldn't trust any bit of consumer electronics against a sustained physical attack by a sufficiently motivated adversary.
Even with this, there's not very much you can do against a state level actor who had physical control of your device and you, and a $5 wrench. Even without having you and being prepared to use violence, a sufficiently motivated state actor will probably get into your device anyway - Apple didn't6 cave to a judge when the FBI wanted them to break every iPhone user's security to get into the San Bernadino shooter's phone, but they didn't get to set a precedent there because someone else broke into that phone for the FBI anyway and they dropped that case...
Much of the low interaction malware is only persistent in memory, so a reboot will clear it until they get their claws back into you. Depending on what the attack path is, that may take some while - and using those attacks is still somewhat risky. "Having to re-pwn a phone every 6 hours" is a lot more risky to an attacker than "someone who never reboots their phone and never updates it."