Sure, because it's *impossible* to write a buffer overflow in C64 BASIC.
Seriously, if you have the know-how and motivation, you can blow through just about any sandbox with code *intended* to do so. It just takes the knowledge of a weak spot in the sandbox's walls.
Quite. And the iPhone's security historically has been... well... not very good. There are almost certainly holes.
Phazer