If the user decides to run a service on their intranet or localhost with a wide open CORS policy, isn't that their choice?
Forgoing CORS and making all inter domain requests user opt-in would make the web experience a lot worse, IMO. Making all intranet or localhost requests user opt-in seems less disruptive.