There have been quite a few of these exploits over the years, where you can trick a program running in locked mode into thinking it's in unlocked mode. It seems like they really need to have completely separate programs to run in locked mode that can't access anything except via defined APIs.