May 2026Unreviewed
Confused ChatGPT: Cross-App Context Poisoning via First-Party APIs
Chao Wang, Somesh Jha, Zhiqiang Lin
Abstract
ChatGPT Apps, launched by OpenAI on Oct. 6, 2025, introduce an app-in-app paradigm in which third-party applications share a single chat context with the user and with every other connected app. The ecosystem grew from 122 apps in Dec. 2025 to 888 by May 2026, yet its security has remained uninvestigated. We identify cross-app context poisoning, a variant of indirect prompt injection distinguished by three properties: 1) the injection persists in the shared chat context across turns; 2) the effe
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
- LLM04Data and Model Poisoning
MITRE ATLAS
- AML.T0020Poison Training Data
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{wang2026confused,
title = {{Confused ChatGPT: Cross-App Context Poisoning via First-Party APIs}},
author = {Chao Wang and Somesh Jha and Zhiqiang Lin},
year = {2026},
month = may,
eprint = {2606.00485},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2606.00485}
}