If the user hasn't visited the subdomain evil.chase.com yet, a http downgrade attack (https://news.ycombinator.com/item?id=18090419) would maybe work.
And requires that if the user had visited chase.com, that chase.com not have includeSubdomains in their HSTS header.