A security vulnerability in the Java Plug-in may allow an applet that is downloaded from a website to bypass the same origin policy and leverage this flaw to execute local applications that are accessible to the user running the untrusted applet.
How it works (public): http://heasman.blogspot.com/2008/03/defeating-same-origin-policy-part-i.html