Please advise whether FreeType is bundled in this case. Given upstream have bumped to address the same issue as Chromium (see tracker bug), it seems like it is, and that the RDEPEND is stale (as was the case with www-client/google-chrome). CCing chromium@ in case they have input.
Okay, I did some poking and it's not bundled and it seems to use the system one. https://chromium-review.googlesource.com/c/chromium/src/+/2485092 looks problematic though, but not sure what CVE it had yet.