OAuth 3.0 does not exist. Over the years, even as early as 2012 when OAuth 2.0 was published, several efforts have attempted to evolve and build upon OAuth 2.0. However, as of November 2024, there is no spec officially called OAuth 3.
The OAuth Working Group at the IETF has not decided to pursue an effort to develop OAuth 3. Instead, OAuth 2.1 is an officially adopted draft by the OAuth Working Group to consolidate and simplify the best practices of OAuth 2.0.