Without the same origin policy CSRF protections would be trivial to circumvent, since you’d be able to read the CSRF token from any page.