That's a signature, so scammers can't send people trusted google.com links and be redirected to a malware site unless the signature verifies with the timestamp. This was standard practice circa 2005.
https://www.google.com/url?q=https://example.com/
Google has had this open redirect forever afaict. I guess they don't consider that a serious threat.
I think the better answer is that this is tracking, just like they do on all of the search results, to see which links are most popular. There still might be a malware surveillance use case but that's not the only one.