Google appears to either not screen ads at all or willingly allows misleading and lying ads and scams to reach its users. They profit off fraud by either laziness and ignorance or malice, by letting "ads" like "Your PDF reader needs an update" through. And they don't act on them when they are reported.
Every single company putting ads up in public is held to a higher standard.
It’s got to be willing ignorance at this point. Gemini Flash can easily distinguish these blatantly malicious ads from the title and redirect URL alone.
I imagine these malware ads offer very high CPCs, and I imagine Google always gets paid (ie no payment fraud). I wouldn’t be surprised if their associative payment fraud detection and banning system works orders of magnitudes better.