If someone were to wire a "hidden" extra OBD connector up inside
the car, connect an OBD Logging device, and log with a hidden
laptop while the car is being serviced for a firmware update,
then "somebody" MIGHT be able to learn how the updates are
accomplished, if they only use the CAN bus.
One probably only needs 3 wires, Ground, CAN-Hi, and CAN-Low
(unless it is a Bluetooth device, then it would also need the 12v
Power wire) .
Of course, there might be non-obvious risks, most people
would not want to be so "sneaky", and the logged data might
be too difficult to decode, or even insufficient to learn much.
So, this is NOT a suggestion, but only a "thought experiment".