$ -> the end of the prompt of a "normal" (i. e. non-root) user
() -> run everything inside in a forked subshell of the current shell
sleep 10 -> "block"/sleep for 10 seconds via the `sleep` executable in your $PATH
; -> after the left-hand side terminates, proceed with the next command on the right-hand side
/tmp/a.out id -> fork and exec the program located at /tmp/a.out with the literal byte sequence "id" on its argument vector
& -> run this command (the whole subshell that () requests) as a background job
When the user exits the shell that spawned the subshell, the whole process group will receive SIGHUP. The backgrounded subshell will still continue running, and after its `sleep` child process terminates, go on to run `/tmp/a.out`.
A background subshell is started that waits 10 seconds and then runs a program with the input "id". That program uses ioctl to send characters to the current TTY.
Since the user exited back to the root shell before the program executed, the `id` command is typed and executed on the root shell.
This is to make the process survive the subsequent logout.
Because this process inherited terminal fds from the parent, it can continue accessing the logged out terminal (now root).