Magic links that embed the OTP inside of a clickable URL have a couple added threat scenarios, mostly revolving around the tenuous connection between app launching URL custom schema and OS/App Store/User Permissions. In some, but not all cases, OS/App Stores make it hard or unlikely for a third party to intercept those URLs, but not always impossible. There's no real central registry for the custom schema between App Stores, for one example.
The successor to custom schemas "Universal Links" (pushed by PWA standards among other things) have an interesting mitigation in requiring the links to be HTTPS, with TLS-verifiable metadata that promises that link is to a domain that the App author clearly controls before passing things on to the App. It's not a perfect mitigation, but a useful one as part of a larger defense in depth, depending on your application/site's threat model.