The threat is XSS. localStorage is readable by any JavaScript on the page, so a single injected script exfiltrates the token and the attacker has a valid session until it expires.
The standard alternative is a cookie the page's JavaScript cannot read:
That moves the risk from "token theft" to "CSRF", which is the easier problem — SameSite plus a CSRF token handles it.
Being honest about the limits: if you have XSS, an attacker can also just make requests with the cookie attached. HttpOnly stops them walking away with a token they can replay elsewhere later, which is a meaningful reduction, not a cure.