A vulnerability in the PayPal API web service authentication flow allows access to an account protected by PayPal 's two-factor authentication (2FA) mechanism.
2FA is an additional security measure that requires the entry of an additional code that is sent to the owner's email address or mobile phone via text message.
The PayPal mobile app cannot be used if the account has two-factor security enabled, but it appears that the process log continues despite the absence of the additional security code and, when the server returns a warning that the connection is protected by an additional code, access to the account in question is blocked.
On iOS, by enabling airplane mode before the 2FA signal returns from the server and then enabling the device to connect again, it is possible to gain access to the account in question that is protected by two-factor security.
When the company was notified of the error, it implemented a temporary fix to the problem.
You can see more here.

