I think the point of this stuff is that, if the user's session is stored in a cookie, and malicious javascript can send HTTP requests to your site (that will use whatever cookie is already present) and read the responses -- they can steer your session without needing to get a hold of a user's session using XSS or anything else.
They already HAVE a hold of the user's session, because they can control the browser, which does.
The point of cross-origin restrictions is to prevent JS loaded from one site from steering the user's session on a different site. (Maybe among other sorts of attacks).
CORS lets you disable those protections. `Access-Control-Allow-Origin: ` disables them entirely.
I could have some of this wrong, I find this stuff confusing too.
But I believe they do not need to "get a hold of a user's session (using XSS or what have you)" in order to steer a user's session under `Access-Control-Allow-Origin: `