I already did report them. The first one was fixed (CVE-2015-6782), got $1k from Google. There are three more they are working on.
In response to your first comment, I should clarify that checking for a valid HTTPS URL SHOULD be sufficient, barring implementation errors in the browser. Of course, if the browser is insecure, all bets are off wrt web security. Implications may range far beyond phishing attacks in that case.
I guess this is a no go for now, then?
>There are three more they are working on.