> Since a head unit typically holds nothing of value to an attacker, one of the more likely attack scenarios using “classic” Android malware is infecting the device to recruit it into a botnet People do pair them with their phones, though. I could imagine a future version of malware like this propagating laterally.
Head units can log location, navigation start and end points, call logs, call audio, and scrape full contact lists. Just off the top of my head.
Also typical Android permissions still apply. The user would need to grant the malicious app contacts, call logs, etc permissions.