As I understand it, you're correct. The Data Controller (Google) is responsible for getting consent, and the Data Processors (the third parties in this case) don't have to get consent themselves.
However, assuming Google's legal basis for processing your personal data is based on consent (rather than fulfillment of a contract or one of the other legal bases), then Google is required to get your unambiguous, opt-in, and non-coerced consent for each specific way your personal data will be used.
It seems likely that Google is covering themselves by acting as a Data Processor, not Data Controller, and the web site using Google is the actual Data Controller. In that case, the web site, not Google, is the one responsible for getting consent.
It is IMO just a mockery of the intent of the law and I wonder when this will be punished.
I personally think GDPR might be a bit strict, but adtech have practically been begging for this for years so acting surprised now doesn't cut it.
So I assume that eventually these performances of consent-gathering will be legally judged meaningless.