Does checking the UA string offer much security? I've always been under the impression that it's essentially user input and not to be trusted. But yeah, that is a pretty nasty CSRF. Good post, thanks.
It would have prevented requests from an authenticated browser (without a mobile UA) from being accepted, reducing the effectiveness of the attack.