So to do this the attacker has to compromise the update servers at $CAR_COMPANY?

no, the update servers at $sketchy_aliexpress_aftermarket_head_unit_company, probably somewhat easier