Spoof checking is unlikely to be your issue. We've long since changed it to simply use Joomlas session now for spoof check strings and no longer uses a separate cookie. So only way it can fail is the spoof check string expired (you sat on the page for a very very long time before submitting it) or your Joomla sessions are not working correctly.
Enable debug mode and maximum error reporting in Joomla global configuration then retry to see if the actual error is exposed. If not check server error logs to see what's going on.
“unknown error” (NSURLErrorDomain:-1) is a browser error. Specifically a Safari error. Ensure your browser is up to date and retry.
But there is also a comprofiler_sessions table which is empty and does not change. Is that the way it is supposed to be?
Yes, that was only used for our old captcha usage.