Before linking a new sign-in method to an existing account, the service requires re-authentication via an already-linked method. An attacker with only an OAuth token cannot pass this gate.
The attacker tries to sign in via SSO with the victim's email. The service detects an existing account and requires re-auth before linking.