CVE-2026-19164 is a Chrome codec vulnerability with sandbox escape potential. The EPSS score of 0.00241 will tempt you to deprioritize it. Don't.
This vulnerability combines three characteristics that have historically compressed the weaponization timeline: it's a codec bug (complex binary parsing under performance pressure creates inherent validation gaps), it enables sandbox escape (neutralizing Chrome's primary defense layer), and it affects a browser with over a billion installations. When these three factors converge, exploitation development doesn't follow the typical months-long pattern—it compresses into weeks, and the attackers who move first aren't criminal commodity exploit markets. They're state-sponsored actors who develop their own chains and don't advertise in exploit kits. EPSS models criminal commoditization latency, not intelligence agency activity.
The historical record is damning: CVE-2021-21148, CVE-2021-21166, and CVE-2022-0609 all followed the same trajectory—high CVSS, low EPSS, deprioritized in enterprise triage, then documented as in-the-wild exploitation within weeks or months of patch release. The pattern isn't coincidental. It's the phenotypic expression of a specific vulnerability genotype: Chrome codec bugs with sandbox escape. You are looking at the third or fourth iteration of the same lesson.
Patch this within your standard patch cycle window. Do not create an exception. Do not defer to next month because the EPSS says it's unlikely. The EPSS is telling you there's no criminal commodity market for this yet—not that state actors aren't already working it. The moment you learn you've lost that bet, you've already lost everything.
If your organization has a deferred-patch queue carrying multiple similar vulnerabilities, treat this CVE as the trigger to audit that queue. Accumulated patch debt against this vulnerability class creates a compounding effect: each deferral normalizes the next one, and the organizational posture degrades predictably.