It is access requirement for something else, which fulfills the criteria of 2FA.
In this case, there is requirement to access the browser and phone.
I guess it’s still safe against leaking of your password only.
It depends on your threat model vs usability/ease of use.
I guess it’s still safe against leaking of your password only.