Daniel J. Bernstein, replying to Solar Designer:

Chromium should fix the code, but is there actually a security issue? Doesn't the protocol limit stream size to packet size? @solardiz


Solar Designer:

Authors have dropped a 0-day on page 9. ;-) Vector implementation of ChaCha20 in NSS/OpenSSL in Chromium will reuse keystream after 256 GB.