It’s high time browsers stop supporting :visited on cross-domain links by default.
No need to remove the feature completely, just not applying :visited on cross-domain links would fix privacy leak, while keeping most legit uses of :visited working fine.