Security researcher Yuebin Sun discovered three critical vulnerabilities in Adobe Acrobat Reader DC for macOS, which can be exploited to gain root access on the system without user awareness. The vulnerabilities are related to the software's update mechanism and can be triggered by a normal user with SIP enabled. Adobe has patched the vulnerabilities, but the patch only addresses the specific issues and does not add sandboxing to the root helper tool. The vulnerabilities highlight the importance of securing software update mechanisms and the potential risks of using complex and fragile autoupdate permission bypasses.