I guess there's the chance that you could do CSRF because you've essentially "set" their CSRF token?
Exactly, cookie forcing/tossing = "set" their CSRF token
I guess there's the chance that you could do CSRF because you've essentially "set" their CSRF token?