At Pwn4Fun, Google delivered a very impressive exploit against Apple Safari launching Calculator as root on Mac OS X. I'll bet it was ocspd they exploited. The CRL handling code in libsecurity is awful, and ocspd runs as root without a sandbox profile.
How can you tell if a process runs as root or is run within a sandbox?
% ps aux|grep ocspd
root 534 0.0 0.0 2442712 2036 ?? Ss 3:53PM 0:00.04 /usr/sbin/ocspd
I don't know how to show the sandbox a running process is contained in, but it's easy enough to show that launchd runs ocspd directly, without sandbox-exec: % grep -A3 ProgramArguments /System/Library/LaunchDaemons/com.apple.ocspd.plist
ProgramArguments
/usr/sbin/ocspd
It's possible for a process to programmatically place itself in a sandbox (see /usr/include/sandbox.h), but a quick look at the source to ocspd and a quick disassembly of what actually ships with OS X 10.9.2 shows ocspd does not do that.