Thanks for the backstory. I note CoyoteDen is a “Level 1 user with 0 points” who understood the implications of what was uncovered when they saw it.
What are the chances that this is an easy-access exploit that the MacOS developers use routinely when putting together/testing updates and, in this instance, they forgot to “close the door” when that update was wrapped up?
That's exactly what I think happened.