No, but I have read stories of auto APIs that are as broken as "change the user ID at the end of the request string, and you can see the entire account details of any other registered user".
That sort of incompetence makes me pause and think.
False equivalency: When the manufacturer fails to secure PII, plus location history, plus control points of the car's internals, etc etc... that's far worse, more obscured, and much more in need of public disclosure than "door's unlocked, free contents!"
It's neither far worse, nor more in need of public disclosure, at all, because it's the exact same, consequentially. Literally, even! In order to take advantage of your "exposed" PII, the adversary needs physical access to your car.