Wonder how good the rest of the security is. The head unit is likely hooked up to a CAN gateway, can it call into telematics. Maybe find some novel way to abuse carplay/aa to call home.
Ah but that is expensive and introduces risk of being caught doing clandestine. It is much more convenient to just use the one already installed and accepted.
In fact, put away all this physical access nonsense and just buy it from the data broker.