Can someone explain what could be done with that and by whom?
replies(4):
And without DNS pointing google.com to that IP address, it's pretty useless.
If they were issued for IP addresses they would have to reissue the certificate every time they spun up a new server. Also it's why if you spin up another server and make DNS point google.com to that server, it would not pass verification since the certificate you will be using on that server is not issued to *.google.com, but rather some other domain you own. The IP address plays no role in certificates.