News.com is reporting the appearance of an OS X exploit. Like previous efforts this one requires that the attacker have an account the machine attacked.
“The risk presented by this exploit is limited by the fact that it can only be exploited by a logged-in user, although the user may also be logged in remotely,” Dino Dai Zovi, a researcher with Matasano Security. “The issue is also mitigated by the fact that a patch has already been released.” More …
Security Update 2006-006 closed this door.