And yet the exploit was known "for years" (so sez TFA). So which is it, security hole from a recently-added feature, or a "hole" that was an open secret for over a decade?
Both, because apparently a feature from 11 years ago is "recently added" per TFA. QuickLook has always worked this way (cached images go in /var on the boot drive).
Something so commonly-known that even I, not exactly a Darwin kernel dev, knew that. Another comment called TFA "blog spam", and I can't argue strongly that they're wrong.
side-bar: how do you know this? is the information about the file structure of linux available somewhere? I've only ever run into this type of thing circumstantially.
Personally, I know it like I know a lot of things: poking around one day, probably looking for something else in the /var directory ("is it /var/log, or /var/logs?"), and "'ello, wot's this?". Best I can recall, I've never had a practical reason to know this, or a lot of other things I know.