Absolutely wild vulnerabilities over at Subaru:
https://arstechnica.com/cars/2025/01/millions-of-subarus-could-be-remotely-unlocked-tracked-due-to-security-flaws/
The researchers were able to get into a Subaru admin account just by guessing the email, and bypassed the "security questions" because they were only checked in the browser.
Just... utter malpractice. No excuses.
(And then it turns out Subaru is storing precise location history of cars for at least a year, possibly indefinitely, and allows remote unlocks of the cars, from this terribly insecure website...)