Why is it not a CORS violation?
The browser needing access and a random website having access are quite different. Seems like a big ol' pile of vulns waiting to happen.