Skip to content
Search
paperMay 2026Unreviewed

Confused ChatGPT: Cross-App Context Poisoning via First-Party APIs

Chao Wang, Somesh Jha, Zhiqiang Lin

Abstract

ChatGPT Apps, launched by OpenAI on Oct. 6, 2025, introduce an app-in-app paradigm in which third-party applications share a single chat context with the user and with every other connected app. The ecosystem grew from 122 apps in Dec. 2025 to 888 by May 2026, yet its security has remained uninvestigated. We identify cross-app context poisoning, a variant of indirect prompt injection distinguished by three properties: 1) the injection persists in the shared chat context across turns; 2) the effe

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM01Prompt Injection
  • LLM04Data and Model Poisoning
MITRE ATLAS
  • AML.T0020Poison Training Data
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@misc{wang2026confused,
  title = {{Confused ChatGPT: Cross-App Context Poisoning via First-Party APIs}},
  author = {Chao Wang and Somesh Jha and Zhiqiang Lin},
  year = {2026},
  month = may,
  eprint = {2606.00485},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2606.00485}
}