The RP can also request not to perform it, but IME Chromium asks for PIN anyway. Firefox is not so insistent.
You can play with parameters here (look for advanced settings):
To be fair, under the blandest definitions of "something that you know", "I know to push this button at the right time" is something that you know (have learned/trained, even). Just because it might be obvious or easily guessed doesn't mean it isn't "something that you know". Anybody can do it, but you know to do it. Most passwords are easily guessed, many PINs are even more easily guessed and have a tiny search space (10^4 = 10,000 combinations), most signatures are easily forged, most "security question" answers are trivially googleable if people answer them honestly and don't treat them as "phone passwords".
(Similar on the "something I am" front: fingerprints are not as unique as people think, confusingly shift over time, and easily spoofed; same, sometimes worse, with "face prints". There are a lot of interesting criticisms out there of current biometric factors.)
The goal of multi-factor authentication in general is that more factors are better, and that the "strength" of each individual factor can be relatively weaker because the strength of the combined multi-factor is often (not always) stronger than the sum of its parts. You can use weaker PINs (or single button presses) than previous passwords if you trust your other factors or the interaction between factors to more than make up for it.
As usual, it is mostly up to your personal threat model if you think you need a stronger factor in place than "I know to push this button". There are Yubikey models where you can require a PIN input every time. There are other similar security keys with biometric unlocks (fingerprint readers). Similarly, too, it is sometimes just fine for someone to say, "based on what I believe my threat model to be and all my other active factors I'm fine with calling 'I know to push this button' as my most common 'something I know'."
I'm a remote worker. My house is more secure than most thanks to my proximity to bad guys.
I have a yubi that I push that puts in 80% of my password. I type the rest.
This saves me time, adds complexity required by corporate.
Why can't I incorporate the key and Chrome password manage?
My cell could be easily lost or compromised (cloned or stolen) so using it as a 2FA always feels silly.