I do think it's pretty amazing that a basic modern authorization system essential has a hard dependency on a 20+ million lines of code web browser, even for native apps. And mostly just because we need a central location to store auth cookies. I'd love to see a stripped-down "auth browser" that has no job other than rendering basic style-free forms (maybe even declared in JSON) and storing cookies. Problem is you have to get the big boys to stop requiring JavaScript for their auth flows.
That said, after doing a decent amount of implementing OAuth2/OpenID Connect, the core profiles are actually pretty reasonable and about what you would want to do if you were starting from scratch. The trick is making sense of all the optional stuff. There have been some efforts[0] to improve that.
The part I've never been able to figure out is why does OAuth2 use tokens at all, rather than generating a key pair and sending the public key with the initial auth request, then signing subsequent requests?
[0]: https://fusionauth.io/articles/oauth/differences-between-oau...