In more detail
Because browsers attach cookies automatically, a malicious page can make your browser submit a form to your bank. Defences are anti-CSRF tokens that an attacker cannot guess, SameSite cookies and checking the Origin header. It differs from Cross-site scripting (XSS): CSRF abuses the site's trust in your browser, XSS abuses your browser's trust in the site.