Essentially it borrows the protections from TLS. Here's a link to the relevant part of the spec: https://fidoalliance.org/specs/fido-u2f-v1.2-ps-20170411/fid...
(Sorry if this comes across as RTFM, but I figured the source is better than my attempt at explaining)