Goofy
Moderator
LINK
Apple has released Security Update 2010-003 for Mac OS X 10.5.8, Mac OS X Server 10.5.8, Mac OS X 10.6.3 and Mac OS X Server 10.6.3, closing a hole revealed at the hacker competition Pwn2Own.
At Pwn2Own, hacker Charlie Miller exploited the loophole through Safari to penetrate a Mac system and win the award in that category. The hole, previously assumed to be a Safari issue, is in fact a bug in the operating systems Apple Type Service (ATS). Apple say that by using specially prepared embedded fonts in documents, it's possible to inject code into a system and execute it.