The thing with this vulnerability is that it is just an XSS.
It has nothing to do with Google apart from the fact they don't run GoogleBot using a recent version of Chrome.
The other thing is that if I understand correctly, this could work without JavaScript. You could just inject HTML <a> tags to inject links in XSS vulnerable website.
PS: Apparently Google Bot has been updated to the latest version of Chromium which means it is even less a vulnerability on Google's side.