New text was added to the settings interface for the egress allowlist. "Egress" means outgoing network connections, and the allowlist is the list of hosts those connections may go to. The text sets out what one entry may look like:
*matches any host, with no port allowed on the bare*localhostnames the local machinehost[:port]is a single host, optionally with a port from 1 to 65535*.host[:port]matches every subdomain of a host, optionally with a port
An entry may not contain a scheme (such as https://), a path, or an IPv6 literal address. The host-list box shows *.corp.example.com as a placeholder example. Separately, a helper cache TTL field (TTL means how long a cached value is kept) is now tagged availableInVersion 1.19367.0.
Anyone filling in the allowlist now sees the accepted formats spelled out, which helps avoid entries that would not be accepted.
The finding does not say which settings screen shows these strings or what the helper cache TTL field controls.