They are passing referer unless the context is an encrypted connection and the resource is on plain HTTP.
Firefox also strips out the path from the URL for third party requests, but only in private browsing mode: https://blog.mozilla.org/security/2018/01/31/preventing-data...
I think this should be the default for all third party domains no matter what the mode. (Really, I'd rather see that header just go away.)