You are wrong. It does. It keeps your user's session from being trivially stolen. In practise this makes successfully executing attacks harder. It's not a _nice_ thing to have, it's essential.
An example of this is an application that asks you to confirm <action> after a POST or w/e. If your XSS vector is not in the new page, then you can't execute <action> as an attacker automatically.
Many, many, applications (not only on the web) implement such a scheme.
A stolen session is MUCH more valuable to an attacker than only a raw XSS.