You just need to "register" a subdomain. So basically any google employee has potentially full access to your system?
What I have learned in place of that is plug holes to minimize attack vectors.
Wow some attack you got there.
But you could have teams with DNS zone delegation who can.create.anything.like.this.google.com
If that malicious actor can install a custom ca too, they can already install whatever spyware they want.
I don't know what setting up a new domain is like but I can't imagine it's something you "just do".
Only to leak your CPU/GPU utilization though as far as I understand it. Those can also be exposed in other ways by legitimate JS/WebGPU by measuring/profiling shader runs/etc.