Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism by appending code to a crafted executable file.
https://support.apple.com/kb/HT205031
https://support.apple.com/kb/HT205030
http://www.securitytracker.com/id/1033275
http://www.securityfocus.com/bid/76343
http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html
http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html