This was reported earlier in the month. Most blogs' source reference is this Yahoo Tech article, that claims:
"Apple is working to fix an iPhone vulnerability that could allow an attacker to remotely install and run unsigned software code with root access to the phone."
http://tech.yahoo.com/news/pcworld/20090702/tc_pcworld/apple...
No details on if Apple dropped the ball or if they were actually working on it in the first place.
My best guess to the vulnerability is the iPhones new MMS capability. They probably had to punch some holes in the sandbox to get MMS media saved on to the phone.