security/nss/lib/mozpkix/lib/pkixnames.cpp
Likewise for Chromium:
trunk/src/net/base/x509_certificate.cc
(I've intentionally not linked these because burdening the relatively heavyweight source viewers with idle HN readers who are mostly going to glaze over and not read once they discover it's tricky C++ code seems unfair)
My guess would be that because it's harder to process multiple wildcards at all, and indeed even the sketchy single wildcard in odd position (which Symantec used to issue and argued wasn't technically prohibited e.g. dev-*.auditcompany.example where auditcompany.example was a domain belonging to Symantec's auditors...) it's less likely anybody goes to the effort to do this even though it's a bad idea.
But I guess if the wrong programmer is assigned the problem they might cheerfully write a nice loop to process wildcards even though it's more effort and the wrong thing so we can't rule out that it has happened somewhere at least once.