Comment by brabel

4 hours ago

Keys in the Secure Enclave never leave the device (or the SE for that matter) and cannot be extracted even physically.

Newer devices support Remote Key Provisioning (RKP), so you still can't export keys but you can import them. (Physical attacks are still possible, just very difficult)