WebHybridClient.java in PayPal 5.3 and earlier for Android ignores SSL errors, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information.
- https://labs.mwrinfosecurity.com/advisories/paypal-remote-code-execution/
No PoCs found on GitHub currently.