It's interesting, but is it much of an attack? Ok, so you can determine what OS your phone is running, but you can do that by coding a QR code that brings them to a webpage that registers it with javascript; you need to direct them to a site regardless to collect your findings from this attack.
You might be able to attack a specific code reader, or a left-handed person who waves their phone over the dots in a different order? Or sneak a malicious code past QA and into the wild.