If your computer is compromised, the 2FA should be somewhere else, not in a keychain.
This is why I like Yubikey and other forms of 2FA (phone based TOTP, mostly).
Even if it is stored in your password manager, it is still useful. Consider the case where your network or website is compromised: the password is compromised and can be reused, but the totp 2fa that is in your password manager still prevents login by anyone who obtained your password. There are many attack scenarios but storing 2fa and enabling autocomplete definitely does not make it useless.
A laptop, or even better, a large, immobile desktop PC, is a much better second factor than a phone, and there is no reason why a user should be forced to go find their phone when they have console access to a much larger device.
Putting a Yubikey semi-permanently on every device and having you do a one-time registration of each device (initially using another already-registered device) should be the default way of implementing 2FA.
It is access requirement for something else, which fulfills the criteria of 2FA.
In this case, there is requirement to access the browser and phone.
I guess it’s still safe against leaking of your password only.
It depends on your threat model vs usability/ease of use.