IOS 6.1 hack lets users see your phone app, place calls
news.cnet.com
news.cnet.com
This isn't Apple being nefarious: this is just Apple being "sloppy" (which I put in quotes, as when you have as many engineers as they do working on as many features as they are, with all of the user interface wedged into the same small set of displays, you are going to expect to have at least a few places like this, and honestly Apple generally does really well at avoiding them).
(As a similar example to this, for an unrelated reason, I just spent the last few hours pulling apart how they do the UI z-ordering of the lock screen, and it is a ton of one-off rules like "if I am adding the notification list, and I already have a battery image up, put it over the battery; otherwise, try to find a thermal warning, but first ask if it considers itself important enough to be rendered on top of the notifications; if not, then see if we have a headset charging display, and try to render on top of that...".)
Seems unlikely, but still :)
That's why on modern devices, a full remote wipe / secure wipe takes seconds instead of hours - only the master filesystem encryption key needs to be zeroed.
also, if you need it you can enable passwords of any length and with more than just digits.
Want to know which employee leaked your super-secret info to a reporter? Arrange for his/her phone to be stolen as they walk down the street chatting on it. Then it's just a quesion of how fast they can remote-wipe it...