How? That quote comes from the person who was fired. She explained what she did because she's proud of it: she injected some code into a web page about unions and organising telling Googlers they had a right to organise.
The Google security team is frankly deeply worrying at this point, and I say that as someone who used to work there on security related topics (but consumer account security, not internal). A small number of them have privileged access to mandatory Chrome extensions that are used for various security objectives, yet they seem to have no qualms about abusing them to advance their own political agendas. Moreover they don't recognise that this is a problem.
Controlling Chrome extensions that can inject JS into arbitrary websites equals root at google.com because everything they do is admin'd via web UIs.
What if you're a law firm who advises companies faced with union action? Is it safe for you to use GSuite or whatever it's called today? My guess is no, because the people who ultimately control Google's IT infrastructure are (a) willing to break the most basic of IT security rules and then boast about it publicly, and (b) many of them are politically extreme by the standards of most of the world.
Most astoundingly of all, I don't believe this is the first time Google has fired people for injecting JS into websites using internal security mechanisms to advance political agendas. In any normal company there'd be a mile of controls, processes and guard dogs surrounding any mechanism that could do this by now as it's been abused before. Apparently Google Security do not have their act together on this.