Head units can log location, navigation start and end points, call logs, call audio, and scrape full contact lists.
Just off the top of my head.
Some head units (working with a 1st party one atm) have two networks: OEM-paid (unlimited data) and user-paid. A 3rd party apk would be consuming all bought traffic quite soon.
Also typical Android permissions still apply. The user would need to grant the malicious app contacts, call logs, etc permissions.
That's scary from a user perspective, but harder to monetise at scale as an attacker. Proxy endpoints are just another commodity (and offer recurring revenue).