For clarity: this exploit isn't to the autonomy or vehicle control system, it's to the infotainment system. It can command auxilliary systems like wipers and doors, and in theory it could do somewhat nefarious stuff like present incorrect data to the user or provide faked waypoints to the navigation system. But it can't actually drive the car.
Really the security model here is fairly reasonable: car control over the motion and autonomy systems is handled by distinct hardware that talks only to one system over a specified protocol, with audited capabilities. And that system then runs the bluetooth and wifi and USB and user interface where the attack surfaces lie.