Here's Google's reply to this particular "vulnerability": http://www.google.com/about/company/rewardprogram.html#logou...
One reason I've also heard cited is that you always want the logout links in your application to work: you want users to be able to terminate their sessions quickly and easily. If you have a CSRF token tied to your user's session and that user happens to click on an old logout link (maybe they had an old tab open or something), the user won't be logged out of the application.
[Disclaimer: I work at Google, but not on any area related to this]