From my understanding you only exclude (protect) one specific socket from the VPN tunnel.
Therefore every other socket you open with the same target is still going through the VPN tunnel.
You have to call protect prepare(...)
on every socket that is established from your device towards Google.