Thanks to Mikeybear to highlighting this one for me on Facebook and Dylan Reeve for a nifty testing tool and an example.. It seems that some Samsung Android handsets have a vulnerability that allows invoking USSD codes from a browser with minimal user interaction.
Not seeing anything about my particular handset, the Samsung Galaxy Nexus, I decided to test it out.