A 0day Safari OSX exploit has been demonstrated at CanSecWest 2007 Conference. The exploit can be triggered simply by visiting a malicious webpage.
According to the contest rules the OSX box was fully patched and the exploit had to require no user intervention. This first attack “owned” the OSX box with user privileges but under the contest rules that was all the exploit had to do. The second OSX box is still up for grabs and for that one a new exploit has to be used and the flaw must lead to a root level compromise.
The contest allowed anyone that logically “owned” the computer to physically own it as well. After the box was exploited instructions could be found in the home folder of the default user for a 2.3Ghz 15" Macbook Pro. Instructions to physically own the 2.3Ghz 17" Macbook Pro can be found in filesystem root.
Details of the exploit are suppose to be released shortly.