Apple Security Advisory 2011-11-08-1 – Multiple vulnerabilities exist in Java 1.6.0_26, the most serious of which may allow an untrusted Java applet to execute arbitrary code outside the Java sandbox.
Follow this link:
Apple Security Advisory 2011-11-08-1