Cyber Security News

PayPal Bug Let Attacker to Steal PayPal Balance with One Click

A security researcher declared the discovery of an unpatched flaw in PayPal that could allow attackers to steal money from users with one click.

Earlier, the expert reported the bug to the PayPal bug bounty program, demonstrating that attackers can steal users’ money by exploiting Clickjacking.

Clickjacking Attack

Clickjacking is also known as a “UI redress attack”. When an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they were intending to click on the top-level page.

According to the expert, “The attacker is “hijacking” clicks meant for their page and routing them to another page, most likely owned by another application, domain, or both”.

“I found that an attacker can steal money from Paypal accounts, Clickjacking on https://www.paypal.com/agreements/approve”, according to the post published by the researcher.

This endpoint is meant for “Billing Agreements” and it should accept only billingAgreementToken. But after the testing, it was found that it can pass another tokens type, and thus leads to stealing money from the victim’s PayPal account.

Sends money to Attacker PayPal

As you click, you will send money to the attacker’s PayPal. Also, the attacker address will be injected as the default billing.

Attacker injected billing address

Attacker injected billing address will be the default one on the victim’s PayPal account. The experts published a PoC exploit for this issue, which according to the expert has yet to be patched. “There are online services that let you add balance using Paypal to your account for example steam! I can use the same exploit and force the user to add money to my account!” reads the post published by the researchers. “Or I can exploit this bug and let the victim create/pay Netflix account for me!”.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Microsoft Releases Emergency Windows 11 Update Following Patch Tuesday Bugs

Microsoft has pushed out an emergency, out-of-band Windows 11 update after its September Patch Tuesday…

4 minutes ago

Top 10 Best Cloud Detection & Response (CDR) Solutions in 2026

CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…

9 minutes ago

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

14 minutes ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

20 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

31 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago