Apple has updated Java on MacOS X with a version that fixes this issue. This vulnerability has been nominated for a Pwnie Award for “best client-side bug” Vulnerability is a class of Java vulnerabilities that allows to completely bypass the Java sandbox and execute arbitrary code remotely in Java enabled web browsers. You should disable Java applets in your browser if you can, or at least consider using NoScript. The overall exploit can be quite complex (mine is over 500 lines but you can make a simpler version)”]
Source: https://blog.cr0.org/2009/05/write-once-own-everyone.html

