It's easy to get wrong, and CORS is not well suited to today's cloud-native microservice era, when your code calls into a million and one different api endpoints hosted by various means.
It used to be that there was a webserver which handled requests, and a static site server, which served the assets, sitting behind a LB connected to the HTTP address.
It made zero sense to do anything cross origin, and it was automatically suspicious. Nowadays, there's N services, all potentially talking to each other, making CORS very difficult to get right.
And more often than not, they are hosted on generic 'api aggregator' endpoints, which make it very hard to get CORS to do anything meaningful with regards to security.
Also, considering you can URL encode stuff, the part saying CORS prevents the exfiltration of data is not true, it just imposes an inconvenience tax.