Ars has a great write up on this that helps explain things in more detail
https://arstechnica.com/security/2025/07/no-phishers-are-not-bypassing-fido-mfa-at-least-not-yet-heres-why/
Turns out this downgrade is specific to Okta (though potentially could be used with other vendors that allow similar fallbacks that ignore the proper FIDO flow).
Okta lets users have a fallback auth that offers a QR code to scan into their own Okta Authenticator app, thus sidestepping using something FIDO compliant entirely. Okta did not follow the FIDO rules for cross-device authentication.
The section of the article titled “How FIDO makes such attacks impossible” is quite interesting, it shows how the FIDO Alliance thought of these kind of downgrades and what the specs do to protect against it, and then how Okta did none of it.