if you are vulnerable to XSS your HttpOnly cookie won't help you.
An example of this is an application that asks you to confirm <action> after a POST or w/e. If your XSS vector is not in the new page, then you can't execute <action> as an attacker automatically.
Many, many, applications (not only on the web) implement such a scheme.
A stolen session is MUCH more valuable to an attacker than only a raw XSS.
HttpOnly is almost totally cosmetic.
I'm probably coming over as too offensive, but you really really don't seem to know what you are even talking about. You are wrong wrong wrong.
http://blog.portswigger.net/2016/05/web-storage-lesser-evil-...