What stops an attacker from spoofing the webcam with a looping video of the subject staring at a camera instead of a still image or holding up a picture?
They detect mask-attacks, replay attacks (put the phone with video into the camera; highjack a webcam input and send a pre-recorded video faking to be real-time from zoom for example), and, of course, still images.
Give it a try!