The WebHybridClient class in PayPal 5.3 and earlier for Android allows remote attackers to execute arbitrary JavaScript on the system.
- https://labs.mwrinfosecurity.com/advisories/paypal-remote-code-execution/
No PoCs found on GitHub currently.