I think it's pretty ridiculous that Apple pours time and effort into stuff like this but apps have been able to steal from your clipboard for years.
It reminds me of the phenomenon when researchers and engineers don't work on something that's useful for everyday users, instead prioritizing what they find exciting and cool. The security team is so busy dealing with absurd edge cases like nation-states attacking your enclave that they don't seem to care to address egregious and obvious holes in the security model like this.
It's not that WebAuthn and passwordless isn't exciting or useful, it's just that there are much bigger fish to fry (clipboard paste, terrible permissions management, non-shitty VPN support, trackers in apps) that Apple seems completely uninterested in addressing.
There really is no excuse, at least not when you're tooting the privacy/security horn so loudly, but let stuff like this pass by.
Edit: have y'all thought of an actual counterargument instead of just downvoting? Is it really too much to ask security engineers at Apple to focus on actual major privacy holes in their OS than things like this?