Yes, that's the way it works. But what's stopping a bad actor from putting up a bogus "Sign in with Google" form on their website solely to harvest credentials?
Now you're talking about phishing sites.
Can you clarify which kind of websites you're referring to?
If I'm asked to sign in with google via oauth, I never type in my password (or username!).