There would have to be a buffer overrun in the text message handling code plus a way to exploit it in 160 characters. That sounds difficult, unless I'm wrong about the fact that the carrier enforces the limit.
I could maybe see doing it with MMS or iMessage. The more I think about it, the more interesting this question is...
Has anyone heard of any exploitable flaws in a phone's SMS software?