GrapheneOS isn't rooted. The issue is their flawed anti-tampering code shipped a new bug breaking compatibility with secure spawning. We have a per-app toggle for secure spawning due to seeing this with other banking/financial/government apps and it works for PayPal's app as the original poster discovered.
If they want to ban arbitrary operating systems, they can use attestation and it can't be fooled the way you're describing. Apps doing this can explicitly verify GrapheneOS and we've convinced some apps to do that. We've also convinced a smaller number to stop doing that at all.
If they want to ban arbitrary operating systems, they can use attestation and it can't be fooled the way you're describing. Apps doing this can explicitly verify GrapheneOS and we've convinced some apps to do that. We've also convinced a smaller number to stop doing that at all.