---
title: "Google Chrome: Update for Active Zero Day"
description: Google Chrome releases patch for Zero Day exploit in the wild. How do bug bounty programs work?
---

[SecureWorld News ](https://www.secureworld.io/industry-news)

# [Google Chrome: Update for Active Zero Day](https://www.secureworld.io/industry-news/google-zero-day-bug-bounty)

 Written by [SecureWorld News Team](https://www.secureworld.io/industry-news/author/secureworld-news-team) | Fri | Nov 1, 2019 | 5:25 PM Z

Google just released Chrome version 78.0.3904.87 for Windows, Mac, and Linux. 

And it closes a Zero Day vulnerability that is being used by attackers.

Says the Chrome Team on its release channel: "Google is aware of reports that an exploit for [CVE-2019-13720](https://cve.mitre.org/cgi-bin/cvename.cgi?name=2019-13720) exists in the wild."

There are no details, yet, on the exploit.

## **Google pays security researchers**

The Google team says the latest version of Chrome addresses two security bugs. Google paid one researcher $7,500, but the payout for the researchers who discovered the Zero Day that is in use is listed as TBD.

And saying thank you is always free.

"We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel."

Read (a small amount) more: [Google Chrome Releases statement](https://chromereleases.googleblog.com/2019/10/stable-channel-update-for-desktop_31.html)

### **How do bug bounty programs work?**

This *out of band* security update from Google is evidence that bug bounty programs are working.

What is the impact on the threat landscape? And how do these security research programs work? Plus, how much do white hat hackers get paid? 

We posed these questions to Brian Gorenc who leads the Zero Day Initiative, which is the world's largest vendor agnostic bug bounty program.

Listen to our interview with Gorenc on *The SecureWorld Sessions* podcast:

[View full post](https://www.secureworld.io/industry-news/google-zero-day-bug-bounty)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "SecureWorld News Team"
  },
  "dateModified" : "2019-11-01T18:01:30.197Z",
  "datePublished" : "2019-11-01T17:25:07Z",
  "headline" : "Google Chrome: Update for Active Zero Day",
  "image" : {
    "@type" : "ImageObject",
    "height" : 724,
    "url" : "https://info.secureworldexpo.com/hubfs/google-reveals-rape-victims.png",
    "width" : 757
  },
  "mainEntityOfPage" : "https://www.secureworld.io/industry-news/google-zero-day-bug-bounty",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60.0,
      "url" : "https://cdn2.hubspot.net/hubfs/2221756/Logos/SWE/SWE_logo_full-long_forWHITEbackgrounds.jpg",
      "width" : 304.46954
    },
    "name" : "SecureWorld News"
  }
}
```