It's not quite milliseconds. According to https://www.documentcloud.org/documents/1302613-ios-security... they've increased the iteration count somewhat:
“The passcode is entangled with the device’s UID, so brute-force attempts must be performed on the device under attack. A large iteration count is used to make each attempt slower. The iteration count is calibrated so that one attempt takes approximately 80 milliseconds.”
This is still an argument for using a longer length code, however, since a simple 4-digit number would only take 800 seconds to brute force.