1. User must enable the installation of apps from unknown sources.
2. User must then find and install malicious app.
3. Malicious app must then try and root phone in order to be able to read the oauth credentials stored in the Tesla app folder.
4. And finally, user must own a Tesla.
Chances of this ever happening in the real world: Zero.