(Note that most YubiKeys also support non-U2F modes, most commonly HOTP (HMAC(shared-secret, counter); counter +=1))
The exchange between browser and key includes the domain of the site. It only works on the same site where registered the key.
AFAIK some websites allow you to use the previous TOTP code for convenience for some more seconds. That makes the total time to impersonate you to be 30 (or whatever was configured while issuing the TOTP secret) plus the grace period websites allow.
Edit: formatting
"a code from your hardware token/authenticator app on your phone/SMS/etc is not phishable"
That certainly seems like it's wrong, and doesn't include an acronym other than SMS.
But apparently there's more depth to this space than I was aware of.
"U2F/WebAuthn is secure because it does origin binding which is not phishable, unlike entering a TOTP or a code from your hardware token or authenticator app or SMS"
Putting the original parenthetical in between the start and end of the main clause definitely makes it easy to misread. I just moved the parenthetical to the end of the sentence.