This was 3 months ago. And he didn't make the
glitch public, which said he will do.
Furthermore the 2FA is checked server-side. So technically it is not possible to bypass 2FA by manipulating the client (in this case: the iOS app).
IMO this was just a bad joke. And far away from being a 'source' to the statement that binance had a security breach.