Session security
Once you have logged in, your device holds a token that says you are already authenticated. That is what stops you logging in again on every page.
Steal that token and you skip the login entirely, including the second factor, because the system is not asking any more. It has already been satisfied. This is why "we have MFA" does not close the subject, and why signing out everywhere matters more than changing your password when a device goes missing. A password change does not necessarily kill a session that is already running.
Checked against the primary source.
