Jason Harris of Unsanity wrote up a detailed whitepaper describing the recent LaunchServices vulnerabilities and the exploits still there even after the help issue was patched. The whitepaper has the following example:
Very clever. Unsanity offers a free utility called Paranoid Android which brings up a dialog when a protocol handler is used that lets the user allow or block the action.
I wonder what Apple's solution will be. I think they'll have to yank the ability to automatically mount disk images. I always thought that seemed a bit dangerous. I can imagine other exploits that could be done based on that.