Sounds like a security flaw. Why don't browsers patch it?
There still is the issue of Mozilla being the only one without a direct incentive to prevent this fix from rolling out. With their whopping 3 percent market share, I doubt they'd be willing to break a web feature we've had for decades.
What use cases would it break? Why do you need a fake URL to show up when the link is hovered?
Preventing them in onclick handlers of a[href] elements would break fewer, but then you have the issue of correlating the redirect with the click. If you simply ban window.href= in the handler, sites could simply use setTimeout or set a flag and have a repeating background task trigger the redirect when the flag is set. Alternatively, you could do something like prevent all redirects X seconds after a link is clicked. Unfortunately, that would only discourage sites that are trying to be fast (like Google). Scam sites are usually slow and bloated anyways.
Why does that AJAX form need to pretend it's a link to a specific URL?
A button would have no problem, and a link that stays on the page would have no problem.
At least in Firefox, one can check easily what the actual URL is before clicking without having to copy-paste elsewhere.
At the risk of insinuating too much, there is a concerning incentive for Bing to provide corrupt links to Chrome.
I can't find a current Bing search ad whose green domain name doesn't match the domain of the destination of the link. Hopefully they've fixed this by now.
At least in Firefox, one can check easily what the actual URL is before clicking without having to copy-paste elsewhere.
It seems to rewrite the link when it gets a mousedown event. Once I right-click, or if I left-click and then drag (to avoid an actual page navigation), the new hovered URL is the google.com/<tracking> version.
Also this only seems to apply to search ads/promoted results. Organic search results don't get rewritten, and copying and pasting a link address gives me the expected destination URL.