Whoever did this would likely select some combination of valuable/soft/flammable targets. Control over a sizable fraction of all vehicles in a country would enable them to create utter pandemonium in tunnels, bridges and underpasses during rush-hour - even larger highways. Aside from fire, I'd imagine that the "disable vehicle on sensing a crash" functionality would end up being hackable as well. Cars on the whole had become less effective as murder weapons up until now, but I suppose that all changes when you can control them remotely via software at scale.
Most vehicles won’t let you reprogram the firmware without power cycling the car. Disable sensing of a crash is definitely its own ECM that is on a high priority bus. I am assuming your common <$40k car. When you head into bmw, merc Benz land this statement changes slightly.
I'd definitely like to think that all of that stuff would be air-gapped, hard-wired and baked into the silicon (and E2E-encrypted, with a Trusted Computing model and auditable supply-chains), but I do worry that people are going to cut corners, fudge things when they're approaching deadlines, and not take into account an appropriate threat model when they're designing this mass-market consumer automotive stuff. The Chrysler hack in 2015 managed to get some fairly low-level remote access to things like the braking system. I'm also considering the possibility that governments might backdoor their own manufacturers with their knowledge in order to gain exploits to systems overseas or to carry out the odd covert assassination.