I'm curious, would it be possible for a malicious person to create a bunch of VMs running the app and brute force VINs to get access to thousands of vehicles and do things all at the same time?
As it is, it already sounds like a theif's dream: no special, suspicious tools required: just a burner phone with an app, walk up to a car, enter the VIN, unlock doors, steal stuff.