I never thought about this, but yes, I think it can be MITM'ed exactly as you described. Same attack can probably be performed on the web, where Smart ID is also a sign in method.
WebAuthn is really what is good enough. Luckily it's well supported on all important platforms so there's really no excuse using anything worse.