I would hope there are specific requirements in the spec/standard WRT protecting the keys and such but I haven't checked to see if that's the case.
Yubico is, according to their website, working towards FIPS 140-2 validation for at least a few of their devices if that has any value to you (no idea about any of the others).
How could they fail silent? Bind to another URL? No, that's a functional failure.
Leak cryptographic material to an attacker? I guess not, unless the attacker controls the web browser, and then all bets are off.
I'm not a security expert, so take with heaps of salt, but I can't see much exposure here.
The point of U2F is to avoid trusting the system, including the browser. Otherwise, what's the point over using just a password manager?
The point is to combat phishing.
Having a hardware dongle is absolutely about preventing malware on the PC from making off with your key material. That's also why you usually have to press a button to complete the U2F flow.
Exceptions to that rule include sites that do things like what GitHub calls "sudo mode", where you have to confirm certain security-sensitive actions with another U2F confirmation. This would require more effort on the attacker's side, as they'd have to trick the victim into performing a U2F confirmation. More effort, but far from impossible: simply display a fake login prompt for the victim, but instead of logging in, perform whatever malicious action you want to perform. Session keys might also be less persistent (they're limited to something like 30 days on Gmail, for example), so that's another small advantage if the attacker wants to keep their access over long periods of time.
Still, for the vast majority of sites and threat models, hardware keys aren't a whole lot better. If it's easier to get adoption for soft keys, that might be a worthwhile trade-off. Natively supported TPM/SEP-backed keys would probably hit the security/UX sweet-spot.
If you add a password manager to the mix, it keeps you safe in the event that only your password manager is compromised, unless you're storing your TOTP secrets in it.
(All of this applies to U2F too, of course.)