How is this really multifactor authentication if the passcode is sent to the same device?

First, the login has to be verified with the specific phone that it is tied to the end user’s account. Second, the phone has to be in the end user’s hand at time of login.